<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search Query Help: Number of Events per Event Code and Total size of those events in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382451#M111750</link>
    <description>&lt;P&gt;Thats super close to what I need.  Was hoping to add the number of events per event code to that.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jul 2019 18:57:45 GMT</pubDate>
    <dc:creator>adalbor</dc:creator>
    <dc:date>2019-07-09T18:57:45Z</dc:date>
    <item>
      <title>Search Query Help: Number of Events per Event Code and Total size of those events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382449#M111748</link>
      <description>&lt;P&gt;Hey All,&lt;/P&gt;

&lt;P&gt;I am trying to calculate the number of events per EventCode along with the total size in kb/mb of all events for that EventCode in a time period.&lt;/P&gt;

&lt;P&gt;I was hoping to table that data by Event Code.&lt;/P&gt;

&lt;P&gt;This is what I have so far but I am struggling with getting a count of each EventCode and listing the sizing in a table.&lt;/P&gt;

&lt;P&gt;index=wineventlog EventCode=4624&lt;BR /&gt;
 | fields _raw &lt;BR /&gt;
 | eval esize=len(_raw) &lt;BR /&gt;
 | stats count as count avg(esize) as avg &lt;BR /&gt;
 | eval bytes=count*avg &lt;BR /&gt;
 | eval kb=bytes/1024 &lt;BR /&gt;
 | eval mb=round(kb/1024,2) &lt;BR /&gt;
 | stats values(kb) as KB, values(mb) AS MB&lt;/P&gt;

&lt;P&gt;This works for a single event code but I need to list all EventCodes and how much storage each are using in total.&lt;/P&gt;

&lt;P&gt;Any help would be great!&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;

&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:16:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382449#M111748</guid>
      <dc:creator>adalbor</dc:creator>
      <dc:date>2020-09-30T01:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query Help: Number of Events per Event Code and Total size of those events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382450#M111749</link>
      <description>&lt;P&gt;can you try something like this? if i'm understanding what you're looking for, you just need to add in EventCode to your fields and stats commands. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=wineventlog 
| fields _raw EventCode
| eval esize=len(_raw)
| stats count as count avg(esize) as avg by EventCode
| eval bytes=count*avg 
| eval kb=bytes/1024 
| eval mb=round(kb/1024,2) 
| stats values(kb) as KB, values(mb) AS MB by EventCode
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 09 Jul 2019 18:45:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382450#M111749</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2019-07-09T18:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query Help: Number of Events per Event Code and Total size of those events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382451#M111750</link>
      <description>&lt;P&gt;Thats super close to what I need.  Was hoping to add the number of events per event code to that.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 18:57:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382451#M111750</guid>
      <dc:creator>adalbor</dc:creator>
      <dc:date>2019-07-09T18:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query Help: Number of Events per Event Code and Total size of those events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382452#M111751</link>
      <description>&lt;P&gt;just add in &lt;CODE&gt;sum(count) as events&lt;/CODE&gt; to the last stats command. think that should do it.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 20:34:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382452#M111751</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2019-07-09T20:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query Help: Number of Events per Event Code and Total size of those events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382453#M111752</link>
      <description>&lt;P&gt;Putting that at the end of my last stats command  doesn't appear to work.  The search returns no results when using that.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 12:46:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382453#M111752</guid>
      <dc:creator>adalbor</dc:creator>
      <dc:date>2019-07-10T12:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query Help: Number of Events per Event Code and Total size of those events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382454#M111753</link>
      <description>&lt;P&gt;&lt;CODE&gt;...| stats sum(count) as events values(kb) as KB, values(mb) AS MB by EventCode&lt;/CODE&gt; doesn’t work?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 13:05:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382454#M111753</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2019-07-10T13:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query Help: Number of Events per Event Code and Total size of those events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382455#M111754</link>
      <description>&lt;P&gt;My hero! Worked perfectly now thank you!&lt;/P&gt;

&lt;P&gt;index=wineventlog &lt;BR /&gt;
     | fields _raw EventCode&lt;BR /&gt;
     | eval esize=len(_raw)&lt;BR /&gt;
     | stats count as count avg(esize) as avg by EventCode&lt;BR /&gt;
     | eval bytes=count*avg &lt;BR /&gt;
     | eval kb=bytes/1024&lt;BR /&gt;
     | eval mb=round(kb/1024,2)&lt;BR /&gt;&lt;BR /&gt;
     | eval gb=round(kb/1024/1024,2) &lt;BR /&gt;
     | stats sum(count) as events values(mb) AS MB, values(gb) as GB by EventCode&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:16:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Query-Help-Number-of-Events-per-Event-Code-and-Total-size/m-p/382455#M111754</guid>
      <dc:creator>adalbor</dc:creator>
      <dc:date>2020-09-30T01:16:34Z</dc:date>
    </item>
  </channel>
</rss>

