Splunk Search

How to reference a tagged field from an eval command?

gilescope
Explorer

We've tagged our hosts which we can search for by 'tag::host', but how do we reference that field from an eval command? Do we first need to rename it or is there a direct way?

Tags (2)
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi gilescope,

this is possible. I used a tag called foo-box for a special host and if you search like this

your base search here | where 'tag::host'="foo-box"

you can use it without any problem.

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi gilescope,

this is possible. I used a tag called foo-box for a special host and if you search like this

your base search here | where 'tag::host'="foo-box"

you can use it without any problem.

cheers, MuS

gilescope
Explorer

ah yes. single quotes is perfect. I tried double quotes but that turns out as a string constant.

MuS
SplunkTrust
SplunkTrust

well where is an eval command .... can you provide an example of yours which does not work?

0 Karma

gilescope
Explorer

Yes this works for search, but I want to include the tag::host field in an eval expression.

0 Karma
Get Updates on the Splunk Community!

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...

Application management with Targeted Application Install for Victoria Experience

Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...