Splunk Search

String matches

dustintroop
Explorer

I have an events for each device with multiple checks as below and i want to find the device count which has "Pass" on all the fields and the device count which has "Fail" in even one field

Device1 check1: Pass check2: Fail check3: Pass
Device2 check1: Pass check2: Pass check3: Pass
Device3 check1: Fail check2: Fail check3: Pass

I'm looking something similar to this

Healthy_Device_Count =1
Un_Healthy_Device_Count=2

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dustintroop,
you could use eval to identify status events, something like this:

your_search
| eval Check=if(check1="Pass" AND check2="Pass" AND check3="Pass","Pass","Fail")
| chart count OVER Check BY Device

Ciao.
Giuseppe

0 Karma

dustintroop
Explorer

Thanks Ciao for the Time & Response. I'm getting error that "The arguments in the if function are invalid". Sorry I think i'm not clear in explaining the problem statement. Let me try again.

Let's say if i have a 100 events from hundred different devices. I want to count the number of events that contains a string "Fail" and the Number of events that doesn't contain the string "Fail"

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dustintroop,
check how you wrote the eval statement: you need to use AND between conditions and quotes for the all the values.
Anyway, you could also have a different approach

 your_search
 | eval Check=if(searchmatch("Fail","Fail","Pass")
 | chart count OVER Device BY Check

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...