Splunk Search

help on where condition

jip31
Motivator

hi

I need to add a where condition on the field 'Time period with no info' below
But the where command doesn't works even if there is an existing field with "08:53:07-000" value
What I have to do please??

| where 'Time period with no info' = "08:53:07-000" 
| stats dc(USERNAME)
Tags (1)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@jip31

Have you tried by renaming column name before where? like below.

YOUR_SEARCH 
| rename "Time period with no info" as Temp 
| where Temp = "08:53:07-000"
0 Karma

jip31
Motivator

now it works thanks

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Great @jip31
Can you please upvote and accept the answer to close this question?

0 Karma

KailA
Contributor

I tried this

| makeresults
| eval "Time period with no info" = "08:53:07-000"
| where 'Time period with no info' = "08:53:07-000"

and it seems to work so could you please send us the full search or maybe an example of your data to have more informations ? 🙂

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...