Splunk Search

How to search and trigger an alert if the same value repeats more than once in a certain field for that particular event?

duraij
Explorer

For example:

:Report=99,10,99

In this case value 99 occurred twice in this field, so I need to pick this event and then create an alert. Please help in solving this issue

0 Karma

somesoni2
SplunkTrust
SplunkTrust

Give this a try (works on Splunk 6.2.0 and above)

your base search | eval temp=split(Report,",") | where mvcount(temp)>mvcount(mvdedup(temp)) | fields - temp
0 Karma

duraij
Explorer

It dint give me any response

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...