Splunk Search

Why is my search eval not returning all expected fields?

New Member

stats count host. Below search only returning "Server and Count" not the Desktop.

index| dedup host | eval "Type"=case(host=="xxx*","Desktop", host!="xxx*","Server") | stats count(host) by Type |  rename count(host) AS Count | table Type Count

Need two row with Server & Desktop. If the host name starts with xxx its Desktop else its Server with count displayed

Tags (3)
0 Karma


eval "Type"=if(match(host,"xxx.*"),"Desktop" ,"Server")
You can use match command like above.


Get Updates on the Splunk Community!

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Admin Console: A Single, Unified Interface for All Your Cloud Admin Needs

WATCH NOWJoin us to learn how the admin console can save you time and give you more control over the Splunk® ...