<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to get count of each source by IP ? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-count-of-each-source-by-IP/m-p/629043#M218491</link>
    <description>&lt;P&gt;Query:&lt;BR /&gt;|tstats count where index=afg-juhb-appl&amp;nbsp; &amp;nbsp;host_ip=*&amp;nbsp; &amp;nbsp; &amp;nbsp;source=*&amp;nbsp; &amp;nbsp; &amp;nbsp;TERM(offer)&lt;BR /&gt;&lt;BR /&gt;i want to get the count of each source by host_ip as shown below.&lt;BR /&gt;output:&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="20%" height="24px"&gt;source&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;11.56.67.12&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;11.56.67.15&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;11.56.67.18&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;11.56.67.19&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%" height="24px"&gt;/app/clts/shift.logs&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;987&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;67&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;67&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;89&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%" height="24px"&gt;/apps/lts/server.logs&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;45&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;45&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;67&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;43&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%" height="24px"&gt;/app/mts/catlog.logs&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;89&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;89&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;65&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;56&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%" height="24px"&gt;/var/http/show.logs&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;12&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;87&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;43&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;65&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Tue, 31 Jan 2023 21:01:24 GMT</pubDate>
    <dc:creator>Vani_26</dc:creator>
    <dc:date>2023-01-31T21:01:24Z</dc:date>
    <item>
      <title>How to get count of each source by IP ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-count-of-each-source-by-IP/m-p/629043#M218491</link>
      <description>&lt;P&gt;Query:&lt;BR /&gt;|tstats count where index=afg-juhb-appl&amp;nbsp; &amp;nbsp;host_ip=*&amp;nbsp; &amp;nbsp; &amp;nbsp;source=*&amp;nbsp; &amp;nbsp; &amp;nbsp;TERM(offer)&lt;BR /&gt;&lt;BR /&gt;i want to get the count of each source by host_ip as shown below.&lt;BR /&gt;output:&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="20%" height="24px"&gt;source&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;11.56.67.12&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;11.56.67.15&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;11.56.67.18&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;11.56.67.19&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%" height="24px"&gt;/app/clts/shift.logs&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;987&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;67&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;67&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;89&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%" height="24px"&gt;/apps/lts/server.logs&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;45&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;45&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;67&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;43&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%" height="24px"&gt;/app/mts/catlog.logs&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;89&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;89&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;65&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;56&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%" height="24px"&gt;/var/http/show.logs&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;12&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;87&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;43&lt;/TD&gt;&lt;TD width="20%" height="24px"&gt;65&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 31 Jan 2023 21:01:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-count-of-each-source-by-IP/m-p/629043#M218491</guid>
      <dc:creator>Vani_26</dc:creator>
      <dc:date>2023-01-31T21:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to get count of each source by IP ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-count-of-each-source-by-IP/m-p/629048#M218493</link>
      <description>&lt;P&gt;What does the current query give you?&amp;nbsp; Is the offer field indexed?&lt;/P&gt;&lt;P&gt;Have you tried grouping by host_ip?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|tstats count where index=afg-juhb-appl host_ip=* source=* TERM(offer) by host_ip&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 31 Jan 2023 21:05:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-count-of-each-source-by-IP/m-p/629048#M218493</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-31T21:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to get count of each source by IP ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-count-of-each-source-by-IP/m-p/629059#M218496</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;1.&amp;nbsp;&lt;SPAN&gt;What does the current query give you?&amp;nbsp; Is the offer field indexed?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;No offrer&amp;nbsp; field is not an index field.&lt;BR /&gt;&lt;BR /&gt;2. When i tried to use the below query i am getting the output as:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;|tstats count where index=afg-juhb-appl host_ip=* source=* TERM(offer) by host_ip&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="1" width="44.44379675357805%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;host_ip&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;&lt;SPAN&gt;11.56.67.12&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;45&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;&lt;SPAN&gt;11.56.67.14&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;56&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;But i am not expecting this output.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 21:54:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-count-of-each-source-by-IP/m-p/629059#M218496</guid>
      <dc:creator>Vani_26</dc:creator>
      <dc:date>2023-01-31T21:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to get count of each source by IP ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-count-of-each-source-by-IP/m-p/629236#M218570</link>
      <description>&lt;P&gt;I should have included source in the &lt;FONT face="courier new,courier"&gt;by&lt;/FONT&gt; clause.&amp;nbsp; Then you can use the &lt;FONT face="courier new,courier"&gt;xyseries&lt;/FONT&gt; command to rearrange the table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|tstats count where index=afg-juhb-appl host_ip=* source=* TERM(offer) by source, host_ip
| xyseries source host_ip count&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 21:08:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-count-of-each-source-by-IP/m-p/629236#M218570</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-02-01T21:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to get count of each source by IP ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-count-of-each-source-by-IP/m-p/629252#M218573</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; it worked&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 23:22:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-count-of-each-source-by-IP/m-p/629252#M218573</guid>
      <dc:creator>Vani_26</dc:creator>
      <dc:date>2023-02-01T23:22:59Z</dc:date>
    </item>
  </channel>
</rss>

