Splunk Search

How do I make a query which finds logs where the value for a field matches?

infcl
Explorer

Log1: id=5 errorA
Log2: id=5 errorB

I would like a query to return the logs with the same id value grouped together. Or more simply, a count of the number of matches.

Thanks.

0 Karma

burwell
SplunkTrust
SplunkTrust

If you want a count you could do your search with | stats count by id

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...