Splunk Search

Using the GUI, how can I search for events related to a specific host?

progress101
New Member

I'm in the process of creating a troubleshooting guide for our networking team. I would like to be able to look up event logs via Splunk Enterprise related to a specific host. The parameters for the search will allow us to view with an interface went up/down as well. How can I properly enter this request into the GUI search & reporting app?

0 Karma

VatsalJagani
Super Champion

Hi @progress101,

You can try searching for index=<your-data-index>. Run the search in verbose mode and below on left-hand side you will see list of fields. Click on below-listed fields and check whether which field is relevant to your host value.

  • host
  • source
  • extracted_host
  • if you don't find host value from above fields you can check value for other fields below

Finally, for example, you end-up noticing host field is having values what you need, search: index=<your-data-index> host="<host-you-want-to-search>"

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

@progress101 ,
Doesn't the host field work for you , for e.g. host="your specific host" ?

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...