<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to Count multiple fields in histogram? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-Count-multiple-fields-in-histogram/m-p/603437#M209997</link>
    <description>&lt;P&gt;I have rows in the form:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="25%"&gt;ID&lt;/TD&gt;
&lt;TD width="25%"&gt;Field1&lt;/TD&gt;
&lt;TD width="25%"&gt;Field2&lt;/TD&gt;
&lt;TD width="25%"&gt;Field3&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And I would like to create a histogram that shows the values of all three fields.&lt;/P&gt;
&lt;P&gt;I can make one for Field1 by doing stats count by Field1 span=1000 but I can't seem to figure out how I would get the other values into the same table. Do I need to do multiple searches and join them? How would I go about doing that?&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jun 2022 16:12:44 GMT</pubDate>
    <dc:creator>rpecka</dc:creator>
    <dc:date>2022-06-28T16:12:44Z</dc:date>
    <item>
      <title>How to Count multiple fields in histogram?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Count-multiple-fields-in-histogram/m-p/603437#M209997</link>
      <description>&lt;P&gt;I have rows in the form:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="25%"&gt;ID&lt;/TD&gt;
&lt;TD width="25%"&gt;Field1&lt;/TD&gt;
&lt;TD width="25%"&gt;Field2&lt;/TD&gt;
&lt;TD width="25%"&gt;Field3&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And I would like to create a histogram that shows the values of all three fields.&lt;/P&gt;
&lt;P&gt;I can make one for Field1 by doing stats count by Field1 span=1000 but I can't seem to figure out how I would get the other values into the same table. Do I need to do multiple searches and join them? How would I go about doing that?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 16:12:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Count-multiple-fields-in-histogram/m-p/603437#M209997</guid>
      <dc:creator>rpecka</dc:creator>
      <dc:date>2022-06-28T16:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Count multiple fields in histogram</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Count-multiple-fields-in-histogram/m-p/603512#M210012</link>
      <description>&lt;P&gt;You can bin every field before counting, e.g.,&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal
| bin date_hour
| bin date_minute
| bin date_second
| stats count by date_hour date_minute date_second&lt;/LI-CODE&gt;&lt;P&gt;Would this work for your scenario?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 06:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Count-multiple-fields-in-histogram/m-p/603512#M210012</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-06-28T06:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Count multiple fields in histogram</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Count-multiple-fields-in-histogram/m-p/603520#M210013</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245205"&gt;@rpecka&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;probably the solution hinted by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;is the correct one, if you want the values of field1 field2 and field3 for each ID, you could try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=your_index
| stats count(field1) AS field1 count(field2) AS field2 count(field3) AS field3 BY ID&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 06:47:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Count-multiple-fields-in-histogram/m-p/603520#M210013</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-06-28T06:47:58Z</dc:date>
    </item>
    <item>
      <title>How to Count multiple fields in histogram?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Count-multiple-fields-in-histogram/m-p/604150#M210155</link>
      <description>&lt;P&gt;It is not clear what you expect the result to look like - for example, if field1 contains either "A", "B", or "C", and field2 contains either "A", "B", or "C", do you want the frequency of "A" in field1 counted separately from the frequency of "A" in field2, etc.?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 16:46:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Count-multiple-fields-in-histogram/m-p/604150#M210155</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-07-01T16:46:15Z</dc:date>
    </item>
  </channel>
</rss>

