Splunk Search

I want to see only the events where a single field is the same( equal) field is "web_container_id"

glenneaton
New Member

how can I display all the events where the "web_container_id" field is the same

Tags (2)
0 Karma

lguinn2
Legend

Put this in the search box and select a time range to search:

web_container_id=111

assuming that you have a field named web_container_id and you are looking for all events with an id of 111...

0 Karma

somesoni2
Revered Legend

Just do a sort by the field and it will arrange all matching events in sequence.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...