Splunk Search

List for a particuar field

taskall78
New Member

I am new to Splunk so any help would appreciated

I have a table

Host Software installed/Uninstalled

1 XYZ Y
RTY N
WER N
YUO Y
2 ABC N
ERT Y
EDC N
3 DEF Y
QWE Y
WSC N

Question: how can I display list of uninstalled/installed software for a particular host?

Tags (4)
0 Karma

sundareshr
Legend

Try this

.... | chart values(Software) as Software over Host by "installed/Uninstalled"
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...