Splunk Search
Highlighted

How search and list the same session ID's occurring in two or more hosts?

Builder

Hi

I have fields created for both sessionId and host. Now I wanna find out the same sessionId happening in two different hosts and list them:

search: index="atg" sessionId="*mob" host="*"

sessionId example =16E4E8BA9480F388B11B3FC35B07732E.svcldprdapp06b-33mob

0 Karma
Highlighted

Re: How search and list the same session ID's occurring in two or more hosts?

SplunkTrust
SplunkTrust

Try something like this

index="atg" sessionId="*mob" host="*" | stats dc(host) as hostCount values(host) as hosts by sessionId | where hostCount>=2

View solution in original post

Highlighted

Re: How search and list the same session ID's occurring in two or more hosts?

Builder

Thanks worked great

0 Karma