Splunk Search

How to return events based on if else rules

rijk
Explorer

I have events like these:

20131212 17:59:07@VE@SANL31 EHDB 121755 CCA@06240@EHAM@ @E 4.47N52.18@Successfully completed
20131212 17:57:17@VE@SANL31 EHDB 121755 @06240@EHAM@ @E 4.47N52.18@Successfully completed

These events belong together because they have the same MessageTime (121755). Using the following subsearch I can return them in pairs:

[search sourcetype="brem" sanl31 eham Successfully completed (cc*) | fields MessageTime] sanl31 eham Successfully completed

How can I refine this search in order to only return the one containing CCA when there is no message not containing the CCA? In this example no event should be returned because both appear. If however the second event was not there I want to keep the first one.

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Maybe a transaction will help.

sourcetype="brem" sanl31 eham Successfully completed | transaction MessageTime | where eventcount = 1 | ...
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Maybe a transaction will help.

sourcetype="brem" sanl31 eham Successfully completed | transaction MessageTime | where eventcount = 1 | ...
---
If this reply helps you, Karma would be appreciated.

rijk
Explorer

Thanks, indeed no subsearches but transactions.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...