I'm in the process of creating a troubleshooting guide for our networking team. I would like to be able to look up event logs via Splunk Enterprise related to a specific host. The parameters for the search will allow us to view with an interface went up/down as well. How can I properly enter this request into the GUI search & reporting app?
Hi @progress101,
You can try searching for index=<your-data-index>
. Run the search in verbose mode and below on left-hand side you will see list of fields. Click on below-listed fields and check whether which field is relevant to your host value.
Finally, for example, you end-up noticing host field is having values what you need, search: index=<your-data-index> host="<host-you-want-to-search>"
@progress101 ,
Doesn't the host
field work for you , for e.g. host="your specific host"
?