Splunk Search

How to write the logic for below condition?

santhannerella
New Member

I have a situation where i will get the success message log when there is response, and there won't be any log in case of failure, I need to show a failure message if i don't get any response. Can you please help me with this.

case:success
Name status Msgtype
F1 null request
F1 null request
F1 Success response

Case: failure

Name status Msgtype
F1 null request
F1 null request
F1 failure response

0 Karma

to4kawa
Ultra Champion

https://docs.splunk.com/Documentation/Splunkbase/splunkbase/Answers/Questions#Tips_for_getting_your_...

your search
| appendpipe [|stats count
| eval message="There is no result"
| where count = 0 | table message ]
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...