<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to display stats results by values(field) in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577648#M201299</link>
    <description>&lt;P&gt;results which I am getting arent accurate and its not making any sense&amp;nbsp;&lt;BR /&gt;I want the count for each value you see in the first value and with the above solution this is not accurate and doesnt work&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pkharbanda1021_0-1638890043433.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17141i1B2E2EDD1DFB8EC2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pkharbanda1021_0-1638890043433.png" alt="pkharbanda1021_0-1638890043433.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Dec 2021 15:14:40 GMT</pubDate>
    <dc:creator>pkharbanda1021</dc:creator>
    <dc:date>2021-12-07T15:14:40Z</dc:date>
    <item>
      <title>how to display stats results by values(field)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577531#M201266</link>
      <description>&lt;P&gt;I am using the following query and trying to display the results using stats but count by field values&lt;BR /&gt;&lt;BR /&gt;search query |&amp;nbsp;&lt;BR /&gt;| table A B C D E&lt;BR /&gt;| stats count values(A) as errors values(B)&amp;nbsp; values(C)&amp;nbsp; by E&lt;/P&gt;&lt;P&gt;Also tried&amp;nbsp;&lt;BR /&gt;| stats&amp;nbsp; count by E A B C [but this messes up everything as this requires every field to have values]&lt;BR /&gt;Current Output&amp;nbsp;&lt;BR /&gt;E&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; count&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; A.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; B&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;C&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Value1.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; X&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; YY&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ZZZ&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Y&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ZZ&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; BBB&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Output&amp;nbsp;&lt;BR /&gt;E&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; count&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; A.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; B&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;C&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Value1.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; X&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; YY&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ZZZ&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Y&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ZZ&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; BBB&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 02:39:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577531#M201266</guid>
      <dc:creator>pkharbanda1021</dc:creator>
      <dc:date>2021-12-07T02:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: how to display stats results by values(field)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577564#M201274</link>
      <description>&lt;LI-CODE lang="markup"&gt;search query | 
| table A B C D E
| fillnull value="N/A" A B C 
| stats count by E A B C&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 07 Dec 2021 07:53:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577564#M201274</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-12-07T07:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: how to display stats results by values(field)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577631#M201290</link>
      <description>&lt;P&gt;this doesn't solve my problem&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 14:29:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577631#M201290</guid>
      <dc:creator>pkharbanda1021</dc:creator>
      <dc:date>2021-12-07T14:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: how to display stats results by values(field)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577640#M201294</link>
      <description>&lt;P&gt;Please explain what is not working for you with this method&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 14:59:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577640#M201294</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-12-07T14:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: how to display stats results by values(field)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577648#M201299</link>
      <description>&lt;P&gt;results which I am getting arent accurate and its not making any sense&amp;nbsp;&lt;BR /&gt;I want the count for each value you see in the first value and with the above solution this is not accurate and doesnt work&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pkharbanda1021_0-1638890043433.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17141i1B2E2EDD1DFB8EC2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="pkharbanda1021_0-1638890043433.png" alt="pkharbanda1021_0-1638890043433.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 15:14:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577648#M201299</guid>
      <dc:creator>pkharbanda1021</dc:creator>
      <dc:date>2021-12-07T15:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: how to display stats results by values(field)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577652#M201301</link>
      <description>&lt;P&gt;Can you share the search you used to get these results?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 15:19:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577652#M201301</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-12-07T15:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: how to display stats results by values(field)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577681#M201321</link>
      <description>&lt;P class="lia-align-left"&gt;for now&amp;nbsp;&lt;BR /&gt;"your base search" | fillnull value=NA errors&lt;BR /&gt;| stats count values(traceid_id) as TraceId&amp;nbsp; by title errors&lt;BR /&gt;&lt;BR /&gt;but I also tried with [this gives me completely different results and I want results by title]&lt;BR /&gt;"your base search" | fillnull value=NA errors traceid_id&amp;nbsp;&lt;BR /&gt;| stats count by title errors&amp;nbsp;traceid_id&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 18:17:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577681#M201321</guid>
      <dc:creator>pkharbanda1021</dc:creator>
      <dc:date>2021-12-07T18:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: how to display stats results by values(field)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577687#M201323</link>
      <description>&lt;P&gt;It is usually easier when you describe your issue with closer to reality examples. Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"your base search" | fillnull value=NA errors traceid_id 
| stats count by title errors traceid_id
| stats list(count) as count list(errors) as errors list(traceid_id) as traceid_id by title&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 07 Dec 2021 18:51:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-display-stats-results-by-values-field/m-p/577687#M201323</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-12-07T18:51:05Z</dc:date>
    </item>
  </channel>
</rss>

