Splunk Search

How to reference a tagged field from an eval command?

gilescope
Explorer

We've tagged our hosts which we can search for by 'tag::host', but how do we reference that field from an eval command? Do we first need to rename it or is there a direct way?

Tags (2)
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi gilescope,

this is possible. I used a tag called foo-box for a special host and if you search like this

your base search here | where 'tag::host'="foo-box"

you can use it without any problem.

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi gilescope,

this is possible. I used a tag called foo-box for a special host and if you search like this

your base search here | where 'tag::host'="foo-box"

you can use it without any problem.

cheers, MuS

gilescope
Explorer

ah yes. single quotes is perfect. I tried double quotes but that turns out as a string constant.

MuS
SplunkTrust
SplunkTrust

well where is an eval command .... can you provide an example of yours which does not work?

0 Karma

gilescope
Explorer

Yes this works for search, but I want to include the tag::host field in an eval expression.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...