Splunk Search

How can I display values of a common field occurring in two different event ID's?

ASTARS47
New Member

There are various event codes like eventID = "123" , eventID ="456", eventID = "789" . There are some "appID"   fields that occurs in both eventID = "123"  AND eventID ="456"  (not all "appID" occur in both these eventID) . So I want to display a list of values from all those "appID"  field which are occurring in both the eventID = "123"  AND eventID ="456" 

Please let me know how can I achieve it. I also have a large data set here.

Thank you.

Labels (5)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

| eventstats values(eventID) as eventids by appID
| where match(eventids, "123") AND match(eventids,"456")
0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...