Splunk Search

How to create a search to show value of fields as Zero having null values and for numeric exact count?

sahil237888
Path Finder

Need help in creating splunk query to show value of fields as Zero having null values and for numeric it should show exact count.

 

For example - 
I want to search for all the events if all fields having specific keywords I am searching.

And for the others, if that keyword is not available in that field value , then it should as 0 count

Labels (2)
Tags (2)
0 Karma

sahil237888
Path Finder

@ITWhisperer  - Basically my requirement is - I have 50 hosts in host field.
So, I need to search for count of "error" keyword in my host list.
If there is a count then it should show the exact count in front of that host , else it should show 0 in parallel to that host.

For, E.g - I run below query - 

index=server_data host IN (server1,server2.....server50) "warning_found"
Then it should show the count of "warning_found" for a specific host. else it should show 0 in parallel to that specific hos

Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It has been said many times before, finding something that doesn't exist is not one of Splunk's strengths.

You could append additional events with zero counts for all the hosts you are interested in, then sum the counts by host.

index=server_data host IN (server1,server2.....server50) "warning_found"
| stats count by host
| append
  [| makeresults
  | eval host=split("server1,server2....server50",",")
  | eval count=0]
| stats sum(count) as count by host
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

This is a bit too generic - please can you give some more concrete examples of the events you want to show and the ones you want to hide?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...