Splunk Search

SPL

uagraw01
Motivator

Hello ,

I am not getting any result while executing below query. Can you please help me to know what i am doing wrong with the eval command with if condition below.

 

IMG_20201119_221004.jpg

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @uagraw01,

the first eval has a space before parenthesis.

Anyway, if you continue to haven't results, debug your search deleting one by one the rows from the end finding the one with problems.

In addition:

  • "| fields *" isn't necessary;
  • how can you have mvindex in the field host?
  • what's the meaning of "| stats values(*) AS *" ?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...