Splunk Search

How to search and sort based on dynamic value?

batham
Explorer

Hi,

I am new to splunk and have a requirement where i have to search the logs which are on 100 servers and i have to figure if each log may consist 2 statements as below ex:

"started step1"

"started step2"

source of log contains actual name of source where i can check the step (location of log /test/test1/ABC.log ,/test/test1/CDE.log,/test/test1/DEF.log) which i figured out based on rex command (using regex) 

I want a table which contain for each log how many step are completed. like:

ABC      started step1  started step2

CDE    started step1

DEF    started step1 started step2

Labels (4)
0 Karma
1 Solution

batham
Explorer
0 Karma

batham
Explorer
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If your problem is resolved, then please click the "Accept as Solution" button to help future readers.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps this will help

index=foo ("started step1" OR "started step2")
```Extract the step into a field```
| rex "(?<step>started step\d)"
```Group the steps by reporting host```
| stats values(step) as steps by host
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...