<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: stats with where clause not filtering in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534415#M151018</link>
    <description>&lt;P&gt;field name is case-sensitive, so&amp;nbsp;&lt;SPAN&gt;senderIP is not same with&amp;nbsp;SenderIP.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=source 
|stats max(_time) as _time, values(from) as Sender, values(rcpt) as Recipients, values(subject) as Subject, values(hops_ip) as SenderIP　by ref |where like(SenderIP, "10.%") | rename ref as Reference&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, there are too many minor mistakes.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Dec 2020 01:08:54 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2020-12-30T01:08:54Z</dc:date>
    <item>
      <title>stats with where clause not filtering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534411#M151017</link>
      <description>&lt;P&gt;Good day everyone,&lt;/P&gt;&lt;P&gt;Ran into following problem,&lt;/P&gt;&lt;P&gt;The query&lt;BR /&gt;index=source | eval time=strftime(_time, "%+)&lt;/P&gt;&lt;P&gt;|stats&lt;/P&gt;&lt;P&gt;max(time)&lt;/P&gt;&lt;P&gt;values(from) as Sender,&lt;/P&gt;&lt;P&gt;values(rcpt) as Recipients,&lt;/P&gt;&lt;P&gt;value(subject) as Subject&lt;/P&gt;&lt;P&gt;values(hops_ip) as SenderIP&lt;/P&gt;&lt;P&gt;values (ref) as Reference&lt;/P&gt;&lt;P&gt;by ref |where like(senderIP, "10.%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure where went wrong, senderIP which is not 10.% is still showing. I did noticed that the ref value appears multiple times for different transaction, that could be the cause? Happy new year in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 00:55:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534411#M151017</guid>
      <dc:creator>thailam</dc:creator>
      <dc:date>2020-12-30T00:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: stats with where clause not filtering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534415#M151018</link>
      <description>&lt;P&gt;field name is case-sensitive, so&amp;nbsp;&lt;SPAN&gt;senderIP is not same with&amp;nbsp;SenderIP.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=source 
|stats max(_time) as _time, values(from) as Sender, values(rcpt) as Recipients, values(subject) as Subject, values(hops_ip) as SenderIP　by ref |where like(SenderIP, "10.%") | rename ref as Reference&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, there are too many minor mistakes.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 01:08:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534415#M151018</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-12-30T01:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: stats with where clause not filtering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534423#M151019</link>
      <description>&lt;P&gt;I have tried the following, however the IP which is not "10%" still showing. Thanks sincerely!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thailam_4-1609298479012.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12391iC8A39E6BCDE5AFFB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="thailam_4-1609298479012.png" alt="thailam_4-1609298479012.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thailam_3-1609298303390.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12390i8425FAFDC45736B8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="thailam_3-1609298303390.png" alt="thailam_3-1609298303390.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 03:22:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534423#M151019</guid>
      <dc:creator>thailam</dc:creator>
      <dc:date>2020-12-30T03:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: stats with where clause not filtering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534433#M151022</link>
      <description>&lt;P&gt;your SenderIP is multivalue. it can't work with &lt;STRONG&gt;where like()&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If you only know the logs, you should make single value from SenderIP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 05:04:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534433#M151022</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-12-30T05:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: stats with where clause not filtering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534435#M151024</link>
      <description>&lt;P&gt;The log has for example "ref" in the log sometime may show different IP. Is anyway i can achieve something similar and to filter away unwanted IP? Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 05:17:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534435#M151024</guid>
      <dc:creator>thailam</dc:creator>
      <dc:date>2020-12-30T05:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: stats with where clause not filtering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534440#M151025</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230057"&gt;@thailam&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You should better filter hops_ip before stats like below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=source hops_ip="10.0.0.0/8"
| stats max(_time) as _time values(from) as Sender values(rcpt) as Recipients values(subject) as Subject values(hops_ip) as SenderIP values(ref) as Reference by ref &lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 30 Dec 2020 07:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534440#M151025</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2020-12-30T07:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: stats with where clause not filtering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534442#M151026</link>
      <description>&lt;P&gt;Hi Scelikok,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just tried that, it works however the sender and recipients is now empty &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thailam_0-1609313651881.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12396i94FD50CE90FD924E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="thailam_0-1609313651881.png" alt="thailam_0-1609313651881.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 07:35:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534442#M151026</guid>
      <dc:creator>thailam</dc:creator>
      <dc:date>2020-12-30T07:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: stats with where clause not filtering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534446#M151028</link>
      <description>&lt;P&gt;Only reason maybe "from" and "rcpt" field names are wrong. Can you please check is there is something wrong about case or typo. Do you see these fields on "Interesting Fields" list?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 08:21:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534446#M151028</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2020-12-30T08:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: stats with where clause not filtering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534454#M151030</link>
      <description>&lt;P&gt;Hi Scelikok&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes that's correct, its not showing right after i've moved the where clause to the top.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thailam_0-1609318381887.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12397i431EBCE4929BEBCA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="thailam_0-1609318381887.png" alt="thailam_0-1609318381887.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 08:55:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534454#M151030</guid>
      <dc:creator>thailam</dc:creator>
      <dc:date>2020-12-30T08:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: stats with where clause not filtering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534647#M151083</link>
      <description>&lt;P&gt;I think this is correct, where can only filter a single value. Have tried, whenever there is only single value it correctly removes it.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 05:36:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534647#M151083</guid>
      <dc:creator>thailam</dc:creator>
      <dc:date>2021-01-04T05:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: stats with where clause not filtering</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534649#M151085</link>
      <description>&lt;P&gt;Due to the log "ref" value may sometime appears multiple times, is there a way i am able to filter by "ref" together with "hdr_mid"?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 05:38:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-with-where-clause-not-filtering/m-p/534649#M151085</guid>
      <dc:creator>thailam</dc:creator>
      <dc:date>2021-01-04T05:38:05Z</dc:date>
    </item>
  </channel>
</rss>

