Splunk Search

Is there a way to get an event by some unique ID(s) ?

socalvin
New Member

I read this but this was almost two years ago:

http://splunk-base.splunk.com/answers/49/does-each-splunk-event-have-a-unique-identifier

Is there any way to retrieve a particular event with one or some of the fields returned from 'search/jobs/export'

Thanks

Calvin

Tags (1)
0 Karma

thisissplunk
Builder

Is this what you're asking for?

index=awesome sourcetype=woah
rename _cd as unique_id
| search unique_id=9320:49207386

0 Karma

pembleton
Path Finder

hey, i join on this question, any update?

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...