<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: show column as count in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61959#M15293</link>
    <description>&lt;P&gt;Thnx every1&lt;/P&gt;</description>
    <pubDate>Tue, 18 Sep 2012 14:13:35 GMT</pubDate>
    <dc:creator>chizops</dc:creator>
    <dc:date>2012-09-18T14:13:35Z</dc:date>
    <item>
      <title>show column as count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61952#M15286</link>
      <description>&lt;P&gt;I'm trying to do a search that looks for a Tag and lists all tags by number of events but also shows the number of source IP address, destination IP addresses and other fields by count.&lt;/P&gt;

&lt;P&gt;So far I have this &lt;/P&gt;

&lt;P&gt;splunk_server="server" index="index" | top 500 tag, severity, source IP, dest ip, source port, dest port | fields - percent&lt;/P&gt;

&lt;P&gt;Although table gives me info that I want I want the source ip, dest ip, source port, dest port fields\columns to show up as a count instead of the actual data so that each row is has a unique tag.&lt;/P&gt;

&lt;P&gt;Can any one tell me how to do this?&lt;/P&gt;

&lt;P&gt;Here's what it looks like so far&lt;/P&gt;

&lt;P&gt;tag           severity   source ip      dest ip        source port   dest port&lt;BR /&gt;
SMB_Auth      high       10.10.16.116   10.10.16.2     1840          445&lt;BR /&gt;
TCP_Probe     low        10.30.22.30    208.120.22.8   49826         6779&lt;/P&gt;

&lt;P&gt;I actually want it to look like this:&lt;/P&gt;

&lt;P&gt;tag           severity   source ip's    dest ip's      source ports   dest ports&lt;BR /&gt;
SMB_Auth      high       200            4000           100            1&lt;BR /&gt;
TCP_Probe     low        10000          165            50             60&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:27:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61952#M15286</guid>
      <dc:creator>chizops</dc:creator>
      <dc:date>2020-09-28T12:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: show column as count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61953#M15287</link>
      <description>&lt;P&gt;You could use the distinct count function of stats command, something similar to this:&lt;/P&gt;

&lt;P&gt;splunk_server="server" index="index" | stats  dc(source IP), dc(dest ip), dc(source port), dc(dest port) by tag &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.4/SearchReference/CommonStatsFunctions"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.4/SearchReference/CommonStatsFunctions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 20:23:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61953#M15287</guid>
      <dc:creator>imrago</dc:creator>
      <dc:date>2012-09-17T20:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: show column as count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61954#M15288</link>
      <description>&lt;P&gt;Does stats give you the information you need ?&lt;/P&gt;

&lt;P&gt;It &lt;EM&gt;feels&lt;/EM&gt; like you're trying to get the number of unique values for each of source IP, dest IP, source port and dest port&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;splunk_server="server" index="index" | stats dc("source ip") as "source ips" dc("dest ip") as "dest ips" dc("source port") as "source ports" dc("dest port") as "dest ports" by tag severity&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;This will count the unique values of each per tag-severity combination.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 20:40:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61954#M15288</guid>
      <dc:creator>jonuwz</dc:creator>
      <dc:date>2012-09-17T20:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: show column as count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61955#M15289</link>
      <description>&lt;P&gt;I think you are looks for stats distinct count&lt;/P&gt;

&lt;P&gt;... | stats dc(source IP) as "source ip's"  dc(dest ip) as "dest ip's"  dc(dest port) as "dest ports" dc(source port) as "source ports" by tag&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 20:45:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61955#M15289</guid>
      <dc:creator>melting</dc:creator>
      <dc:date>2012-09-17T20:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: show column as count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61956#M15290</link>
      <description>&lt;P&gt;Woohoo we all go it!&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 20:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61956#M15290</guid>
      <dc:creator>melting</dc:creator>
      <dc:date>2012-09-17T20:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: show column as count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61957#M15291</link>
      <description>&lt;P&gt;Thnx man. I should have given u the link award points as you were first. This worked out well. Thanks a lot.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 22:40:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61957#M15291</guid>
      <dc:creator>chizops</dc:creator>
      <dc:date>2012-09-17T22:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: show column as count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61958#M15292</link>
      <description>&lt;P&gt;Ahh, was able to after all.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 22:41:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61958#M15292</guid>
      <dc:creator>chizops</dc:creator>
      <dc:date>2012-09-17T22:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: show column as count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61959#M15293</link>
      <description>&lt;P&gt;Thnx every1&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2012 14:13:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/show-column-as-count/m-p/61959#M15293</guid>
      <dc:creator>chizops</dc:creator>
      <dc:date>2012-09-18T14:13:35Z</dc:date>
    </item>
  </channel>
</rss>

