Splunk Search

String matches

dustintroop
Explorer

I have an events for each device with multiple checks as below and i want to find the device count which has "Pass" on all the fields and the device count which has "Fail" in even one field

Device1 check1: Pass check2: Fail check3: Pass
Device2 check1: Pass check2: Pass check3: Pass
Device3 check1: Fail check2: Fail check3: Pass

I'm looking something similar to this

Healthy_Device_Count =1
Un_Healthy_Device_Count=2

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dustintroop,
you could use eval to identify status events, something like this:

your_search
| eval Check=if(check1="Pass" AND check2="Pass" AND check3="Pass","Pass","Fail")
| chart count OVER Check BY Device

Ciao.
Giuseppe

0 Karma

dustintroop
Explorer

Thanks Ciao for the Time & Response. I'm getting error that "The arguments in the if function are invalid". Sorry I think i'm not clear in explaining the problem statement. Let me try again.

Let's say if i have a 100 events from hundred different devices. I want to count the number of events that contains a string "Fail" and the Number of events that doesn't contain the string "Fail"

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dustintroop,
check how you wrote the eval statement: you need to use AND between conditions and quotes for the all the values.
Anyway, you could also have a different approach

 your_search
 | eval Check=if(searchmatch("Fail","Fail","Pass")
 | chart count OVER Device BY Check

Ciao.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...