Splunk Search

List for a particuar field

taskall78
New Member

I am new to Splunk so any help would appreciated

I have a table

Host Software installed/Uninstalled

1 XYZ Y
RTY N
WER N
YUO Y
2 ABC N
ERT Y
EDC N
3 DEF Y
QWE Y
WSC N

Question: how can I display list of uninstalled/installed software for a particular host?

Tags (4)
0 Karma

sundareshr
Legend

Try this

.... | chart values(Software) as Software over Host by "installed/Uninstalled"
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Seamless IT/OT Security: A Hands-On Look at the Cisco Cyber Vision Splunk Add-on

With just a few clicks, you can ingest critical OT asset details, vulnerabilities, baseline deviations, ...