Splunk Search

Search command for different PC's

Rhuen
New Member

Hy,

i have create a Dashboard with Error Logs.
1 for all pc's: Computername="*", it works, i see all PC's but which command is the right to see only 2 or 3 PC's with Computername:
Client1 and Client2?!
I was try:
...Computername="Client1,Client"...Computername="Client1" Computername="Client2"...and so on, nothing is working.

I know it works with "Client*" then i see Client1, and Client2, but the Computernames are MAC-Adress...Client1 and Client2 name is only a example.

I hope you know what i mean :-).

This are my complete search string:

source="WMI:WinEventLog:*" ComputerName="*"  | stats count count(eval(Type="Warnung")) as warnings count(eval(Type="Fehler")) as errors by host

greets.

Tags (3)
0 Karma
1 Solution

Ayn
Legend

If you want to search for multiple values of ComputerName you could just OR them together:

ComputerName="Client1" OR ComputerName="Client2" OR ...

View solution in original post

jtrimmi1
Explorer

I think now you can do something like this :

source="WMI:WinEventLog:*" ComputerName IN ("Client1","Client2","Client3","Client4")

Rhuen
New Member

Haha omg you right Ayn 🙂 so simple, thx.

0 Karma

Ayn
Legend

If you want to search for multiple values of ComputerName you could just OR them together:

ComputerName="Client1" OR ComputerName="Client2" OR ...
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...