Splunk Search

Is there a way to show my data that only fail and never pass at a later time frame?

Shhiii
New Member

I'm trying to filter data that is either pass or fail. Some of my data points that are fail return as a pass as well. Is there a way to show my data that only fail and never pass at a later time frame?

Labels (1)
0 Karma

Shhiii
New Member

I tried to think of a way to use dedup but can not find a solution with that function 

 

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...