<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you get counts with wildcards? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402119#M116379</link>
    <description>&lt;P&gt;How do I make that work on an enterprise query that uses an index?  ie "index=mylog path='/routeX/*' ?&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jan 2019 18:33:11 GMT</pubDate>
    <dc:creator>wfresch</dc:creator>
    <dc:date>2019-01-10T18:33:11Z</dc:date>
    <item>
      <title>How do you get counts with wildcards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402112#M116372</link>
      <description>&lt;P&gt;Suppose I have the following data, but I don't know the GUIDs ahead of time:&lt;/P&gt;

&lt;P&gt;Path&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/boat/826ec68b-cc87-41f9-b93b-5bfae6f21c52/duck
/car/39bdd442-167b-46b0-95fd-1e8e0423e7f8/fox
/car/2c2d27d4-4c07-460e-8c0e-11aad4e4c34a/cat
/car/2c2d27d4-4c07-460e-8c0e-11aad4e4c34a/fox
/car/2c2d27d4-4c07-460e-8c0e-11aad4e4c34a
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'd like to get counts like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Count    Path
1        /boat/*/duck
2        /car/*/fox
1        /car/*/cat
1        /car/*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is  this possible? I can even get &lt;EM&gt;close&lt;/EM&gt; to this. I'd be happy — like, a count of 4 for "/car/*" would still be better than nothing.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 14:54:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402112#M116372</guid>
      <dc:creator>wfresch</dc:creator>
      <dc:date>2019-01-10T14:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: How do you get counts with wildcards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402113#M116373</link>
      <description>&lt;P&gt;Hi Martin,&lt;/P&gt;

&lt;P&gt;Please find below the run anywhere query, one question is your path format is always same? if not we can think about negative indexing in mvindex. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|  makeresults  count=5
| rename comment as "start of data preparation"
| streamstats count as id
| eval path = case(id=1,"/boat/826ec68b-cc87-41f9-b93b-5bfae6f21c52/duck",id=2,"/car/39bdd442-167b-46b0-95fd-1e8e0423e7f8/fox",id=3,"/car/2c2d27d4-4c07-460e-8c0e-11aad4e4c34a/cat",id=4,"/car/2c2d27d4-4c07-460e-8c0e-11aad4e4c34a/fox",id=5,"/car/2c2d27d4-4c07-460e-8c0e-11aad4e4c34a")
| table path
| eval splitted_path = split(path,"/")
| eval needed_path = "/".mvindex(splitted_path,1)."/".if(isnull(mvindex(splitted_path,3))," ",mvindex(splitted_path,3))
| stats count by needed_path
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Sid&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 15:56:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402113#M116373</guid>
      <dc:creator>sdchakraborty</dc:creator>
      <dc:date>2019-01-10T15:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do you get counts with wildcards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402114#M116374</link>
      <description>&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval path = "/boat/826ec68b-cc87-41f9-b93b-5bfae6f21c52/duck /car/39bdd442-167b-46b0-95fd-1e8e0423e7f8/fox /car/2c2d27d4-4c07-460e-8c0e-11aad4e4c34a/cat /car/2c2d27d4-4c07-460e-8c0e-11aad4e4c34a/fox /car/2c2d27d4-4c07-460e-8c0e-11aad4e4c34a" 
| makemv path 
| mvexpand path 

| rename COMMENT AS "Everything above generates sample event data; everything below is your solution"

| eval orig_path = path 
| rex field=path mode=sed "s%(/[^/]+)/[^/]+%\1%"
| stats count by path
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 10 Jan 2019 16:25:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402114#M116374</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-10T16:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: How do you get counts with wildcards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402115#M116375</link>
      <description>&lt;P&gt;will this work, even if I don't know the actual GUIDs ahead of time?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 17:12:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402115#M116375</guid>
      <dc:creator>wfresch</dc:creator>
      <dc:date>2019-01-10T17:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do you get counts with wildcards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402116#M116376</link>
      <description>&lt;P&gt;will this work, even if I don't know the actual GUIDs ahead of time?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 17:13:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402116#M116376</guid>
      <dc:creator>wfresch</dc:creator>
      <dc:date>2019-01-10T17:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: How do you get counts with wildcards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402117#M116377</link>
      <description>&lt;P&gt;Yes, it blindly strips off everything between the 2nd and 3rd &lt;CODE&gt;/&lt;/CODE&gt; character (including one of the &lt;CODE&gt;/&lt;/CODE&gt; characters).&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 17:15:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402117#M116377</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-10T17:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: How do you get counts with wildcards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402118#M116378</link>
      <description>&lt;P&gt;Yes it will work.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 17:22:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402118#M116378</guid>
      <dc:creator>sdchakraborty</dc:creator>
      <dc:date>2019-01-10T17:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: How do you get counts with wildcards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402119#M116379</link>
      <description>&lt;P&gt;How do I make that work on an enterprise query that uses an index?  ie "index=mylog path='/routeX/*' ?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 18:33:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402119#M116379</guid>
      <dc:creator>wfresch</dc:creator>
      <dc:date>2019-01-10T18:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: How do you get counts with wildcards?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402120#M116380</link>
      <description>&lt;P&gt;Use your search and then add on lines 8-10 of my solution.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 19:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-get-counts-with-wildcards/m-p/402120#M116380</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-10T19:00:17Z</dc:date>
    </item>
  </channel>
</rss>

