<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Group events based on content of field? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Group-events-based-on-content-of-field/m-p/621033#M215872</link>
    <description>&lt;P&gt;I have the following table of activities:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;Internal&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;External&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;Direction&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;1.1.1.1&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;2.2.2.2&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;Outbound&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;3.3.3.3&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;4.4.4.4&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;Inbound&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;5.5.5.5&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;4.4.4.4&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;Inbound&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;1.1.1.1&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;8.8.8.8&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;Outbound&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to group them by either Internal OR External, based on what is in the Direction field, if its Outbound I want to group by Internal , if its Inbound I want to group by External, and get the count.&lt;BR /&gt;I would like to get the following table as a result:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;Internal&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;External&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;Count&lt;/TD&gt;
&lt;TD width="8.333333333333334%"&gt;Grouped by&lt;/TD&gt;
&lt;TD width="8.333333333333334%"&gt;Direction&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;1.1.1.1&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;2.2.2.2&lt;BR /&gt;8.8.8.8&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;2&lt;/TD&gt;
&lt;TD width="8.333333333333334%"&gt;1.1.1.1&lt;/TD&gt;
&lt;TD width="8.333333333333334%"&gt;Outbound&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;3.3.3.3&lt;BR /&gt;5.5.5.5&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;4.4.4.4&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;2&lt;/TD&gt;
&lt;TD width="8.333333333333334%"&gt;4.4.4.4&lt;/TD&gt;
&lt;TD width="8.333333333333334%"&gt;Inbound&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Nov 2022 15:04:37 GMT</pubDate>
    <dc:creator>KMoryson</dc:creator>
    <dc:date>2022-11-16T15:04:37Z</dc:date>
    <item>
      <title>Group events based on content of field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-events-based-on-content-of-field/m-p/621033#M215872</link>
      <description>&lt;P&gt;I have the following table of activities:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;Internal&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;External&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;Direction&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;1.1.1.1&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;2.2.2.2&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;Outbound&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;3.3.3.3&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;4.4.4.4&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;Inbound&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;5.5.5.5&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;4.4.4.4&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;Inbound&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;1.1.1.1&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;8.8.8.8&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;Outbound&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to group them by either Internal OR External, based on what is in the Direction field, if its Outbound I want to group by Internal , if its Inbound I want to group by External, and get the count.&lt;BR /&gt;I would like to get the following table as a result:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;Internal&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;External&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;Count&lt;/TD&gt;
&lt;TD width="8.333333333333334%"&gt;Grouped by&lt;/TD&gt;
&lt;TD width="8.333333333333334%"&gt;Direction&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;1.1.1.1&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;2.2.2.2&lt;BR /&gt;8.8.8.8&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;2&lt;/TD&gt;
&lt;TD width="8.333333333333334%"&gt;1.1.1.1&lt;/TD&gt;
&lt;TD width="8.333333333333334%"&gt;Outbound&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;3.3.3.3&lt;BR /&gt;5.5.5.5&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="25px"&gt;4.4.4.4&lt;/TD&gt;
&lt;TD width="16.666666666666668%" height="25px"&gt;2&lt;/TD&gt;
&lt;TD width="8.333333333333334%"&gt;4.4.4.4&lt;/TD&gt;
&lt;TD width="8.333333333333334%"&gt;Inbound&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 15:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-events-based-on-content-of-field/m-p/621033#M215872</guid>
      <dc:creator>KMoryson</dc:creator>
      <dc:date>2022-11-16T15:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Group events based on content of field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-events-based-on-content-of-field/m-p/621034#M215873</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eventstats values(Internal) as internals by External
| eventstats values(External) as externals by Internal
| eval groupby=if(Direction="Outbound",Internal,External)
| stats values(internals) as internals values(externals) as externals values(Direction) as Direction by groupby
| eval count=max(mvcount(internals), mvcount(externals))&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 16 Nov 2022 10:07:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-events-based-on-content-of-field/m-p/621034#M215873</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-11-16T10:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Group events based on content of field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Group-events-based-on-content-of-field/m-p/621036#M215874</link>
      <description>&lt;P&gt;So effectively you want to group by src_ip&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;...your existing query...
| eval src_ip = if(Direction="Outbound",Internal,External)
| stats values(Internal) as Internal values(External) as External count values(Direction) as Direction by src_ip&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 16 Nov 2022 10:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Group-events-based-on-content-of-field/m-p/621036#M215874</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2022-11-16T10:44:07Z</dc:date>
    </item>
  </channel>
</rss>

