<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extract from Multiple Fields and Consolidate using Stats Count in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692794#M235791</link>
    <description>&lt;P&gt;OK try it with double quotes on the stats command (which is counter-intuitive!)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="apigee" (ProxyPath="/xyz" OR ProxyPath="/abc") AND StatusCode=200 | eval "BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode" = coalesce('BackendResponse.content.reasonCode', 'ConsumerResponse.content.reasonCode') | stats count by "BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode"&lt;/LI-CODE&gt;</description>
    <pubDate>Tue, 09 Jul 2024 16:50:56 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-07-09T16:50:56Z</dc:date>
    <item>
      <title>Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692680#M235748</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I have two different fields (Ex. A and B). Value A will come for some results and B will come for some. While I am using below query, it is only pulling A or B.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="XYZ"  (ProxyPath="/xyz" OR ProxyPath="/abc") AND StatusCode=200
| stats count by A StatusCode - only A events are getting displayed

index="XYZ"  (ProxyPath="/xyz" OR ProxyPath="/abc") AND StatusCode=200
| stats count by B StatusCode - only B events are getting displayed

index="XYZ"  (ProxyPath="/xyz" OR ProxyPath="/abc") AND StatusCode=200
| stats count by A B StatusCode - it is not displaying any table&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to display both A and B colums combined and have the status code as well in the table?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 23:05:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692680#M235748</guid>
      <dc:creator>sridharadurthi</dc:creator>
      <dc:date>2024-07-08T23:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692682#M235749</link>
      <description>&lt;P&gt;You need to first think through what the problem you are trying to solve by using sample data. &amp;nbsp;Let's say the search &lt;SPAN&gt;index="XYZ"&amp;nbsp; (ProxyPath="/xyz" OR ProxyPath="/abc") AND StatusCode=200 returns the following results.&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="1" width="56.25%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%"&gt;StatusCode&lt;/TD&gt;&lt;TD width="25%"&gt;A&lt;/TD&gt;&lt;TD width="25%"&gt;B&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;200&lt;/TD&gt;&lt;TD width="25%"&gt;some A value&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;200&lt;/TD&gt;&lt;TD width="25%"&gt;some other A value&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;200&lt;/TD&gt;&lt;TD width="25%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="25%"&gt;Some B value&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Some other B value&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;Even more A value&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Can you show the result table that you are looking for?&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;How to display both A and B colums combined and have the status code as well in the table?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;If A and B do not exist in the same event, I see no meaningful way to display both of them.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 21:00:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692682#M235749</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-07-08T21:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692683#M235750</link>
      <description>&lt;P&gt;Thanks for swift reply&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;. Here is the sample table I am looking for&lt;/P&gt;&lt;TABLE border="1" width="56.25%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%"&gt;StatusCode&lt;/TD&gt;&lt;TD width="25%"&gt;A or B&lt;/TD&gt;&lt;TD width="25%"&gt;Count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;200&lt;/TD&gt;&lt;TD width="25%"&gt;some A/B value&lt;/TD&gt;&lt;TD width="25%"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;200&lt;/TD&gt;&lt;TD width="25%"&gt;some A/B value&lt;/TD&gt;&lt;TD width="25%"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;200&lt;/TD&gt;&lt;TD width="25%"&gt;some A/B value&lt;/TD&gt;&lt;TD width="25%"&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;some A/B value&lt;/TD&gt;&lt;TD&gt;8&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;some A/B value&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;A &amp;amp; B coulmns should come together as one and based on their values it should add to the count. More detailed way&lt;/P&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%"&gt;StatusCode&lt;/TD&gt;&lt;TD width="25%"&gt;A or B&lt;/TD&gt;&lt;TD width="25%"&gt;Count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;200&lt;/TD&gt;&lt;TD width="25%"&gt;Upgrade&lt;/TD&gt;&lt;TD width="25%"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;200&lt;/TD&gt;&lt;TD width="25%"&gt;Downgrade&lt;/TD&gt;&lt;TD width="25%"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;200&lt;/TD&gt;&lt;TD width="25%"&gt;Retain&lt;/TD&gt;&lt;TD width="25%"&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;Cancel&lt;/TD&gt;&lt;TD&gt;8&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;New Customer&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 21:09:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692683#M235750</guid>
      <dc:creator>sridharadurthi</dc:creator>
      <dc:date>2024-07-08T21:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692685#M235751</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;SPAN&gt;A &amp;amp; B coulmns should come together as one and based on their values it should add to the count. &lt;/SPAN&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This is clearer than the original description. &amp;nbsp;If A and B should come together, they have to be combined before groupby, and used as a single groupby. &amp;nbsp;The reason why your first attempt did produce results is because as two separate groupby terms, both must exist in the same events.&lt;/P&gt;&lt;P&gt;The solution will depend on whether A and B are mutually exclusive. &amp;nbsp;From your original result, it seems that they are exclusive. &amp;nbsp;So,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="XYZ"  (ProxyPath="/xyz" OR ProxyPath="/abc") AND StatusCode=200
| eval "A OR B" = coalesce(A, B)
| stats count by "A OR B" StatusCode&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 23:11:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692685#M235751</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-07-08T23:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692687#M235752</link>
      <description>&lt;P&gt;When I am trying your query, it is showing that number events on the top. But not displayin the results in the statistics. Like below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sridharadurthi_0-1720474272458.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31644i537ED78B170B7866/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sridharadurthi_0-1720474272458.png" alt="sridharadurthi_0-1720474272458.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 21:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692687#M235752</guid>
      <dc:creator>sridharadurthi</dc:creator>
      <dc:date>2024-07-08T21:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692689#M235753</link>
      <description>&lt;P&gt;Please share the search which is giving this result.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2024 22:19:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692689#M235753</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-07-08T22:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692693#M235756</link>
      <description>&lt;P&gt;This only means that your data set is not as you described. &amp;nbsp;Alternatively, there was some mistake in your search as &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;speculated. &amp;nbsp;For example, maybe you misspelled A or B (these are not real field names I am certain).&lt;/P&gt;&lt;P&gt;I can run my code with this mock dataset:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;A&lt;/TD&gt;&lt;TD&gt;B&lt;/TD&gt;&lt;TD&gt;StatusCode&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Upgrade&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Downgrade&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Upgrade&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Retain&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Cancel&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Cancel&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Cancel&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Cancel&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Cancel&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Cancel&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Cancel&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Cancel&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Retain&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Retain&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Retain&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Retain&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Retain&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Retain&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;Retain&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Retain&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;If you manually count, this dataset should give your mock result and it does. &amp;nbsp;Here is full emulation that you can run an compare with real data:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults format=csv data="StatusCode, A, B
200, Upgrade,
200, , Downgrade
200, , Upgrade
200, Retain,
200, , Cancel
200,Cancel,
200, , Cancel
200,Cancel,
200, , Cancel
200,Cancel,
200, , Cancel
200,Cancel,
200, , Retain
200, Retain,
200, Retain,
200, , Retain
200, Retain,
200, Retain,
200, , Retain
200, Retain,
200, Retain,
200, New Customer,
200, , New Customer
200, , New Customer
200, New Customer,
200, , New Customer"
``` the above emulates
index="XYZ"  (ProxyPath="/xyz" OR ProxyPath="/abc") AND StatusCode=200
```
| eval "A OR B" = coalesce(A, B)
| stats count by "A OR B" StatusCode&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The output is exactly like your mock result:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;A OR B&lt;/TD&gt;&lt;TD&gt;StatusCode&lt;/TD&gt;&lt;TD&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Cancel&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;8&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Downgrade&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;New Customer&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Retain&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Upgrade&lt;/TD&gt;&lt;TD&gt;200&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 08 Jul 2024 23:10:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692693#M235756</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-07-08T23:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692766#M235780</link>
      <description>&lt;P&gt;this is the query which I am using to filter the data&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="apigee" (ProxyPath="/xyz" OR ProxyPath="/abc") AND StatusCode=200 | eval "BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode" = coalesce(BackendResponse.content.reasonCode, ConsumerResponse.content.reasonCode)
| stats count by "BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode" StatusCode&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 13:40:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692766#M235780</guid>
      <dc:creator>sridharadurthi</dc:creator>
      <dc:date>2024-07-09T13:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692768#M235781</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;this is the query which I am using to filter the data&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index="apigee" (ProxyPath="/xyz" OR ProxyPath="/abc") AND StatusCode=200 | eval "BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode" = coalesce(BackendResponse.content.reasonCode, ConsumerResponse.content.reasonCode) | stats count by "BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode" StatusCode&lt;/LI-CODE&gt;
&lt;P&gt;It is showing the event count, but it is not generating the results. Highlited the same.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sridharadurthi_0-1720532706875.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31652i97B1460CC1E0D818/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sridharadurthi_0-1720532706875.png" alt="sridharadurthi_0-1720532706875.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 14:21:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692768#M235781</guid>
      <dc:creator>sridharadurthi</dc:creator>
      <dc:date>2024-07-09T14:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692774#M235782</link>
      <description>&lt;P&gt;When field names have special characters in, they often need single quotes around them (double if they are on the left of the assignment). Try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval "BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode" = coalesce('BackendResponse.content.reasonCode', 'ConsumerResponse.content.reasonCode')
| stats count by 'BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode' StatusCode&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 09 Jul 2024 15:23:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692774#M235782</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-07-09T15:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692777#M235783</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;, I tried but no luck &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; . It is displaying the count but not displaying the stats&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sridharadurthi_1-1720539436378.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31654i60010108EF1FC76E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sridharadurthi_1-1720539436378.png" alt="sridharadurthi_1-1720539436378.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 15:37:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692777#M235783</guid>
      <dc:creator>sridharadurthi</dc:creator>
      <dc:date>2024-07-09T15:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692786#M235786</link>
      <description>&lt;P&gt;Try without StatusCode on the stats&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="apigee" (ProxyPath="/xyz" OR ProxyPath="/abc") AND StatusCode=200 | eval "BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode" = coalesce('BackendResponse.content.reasonCode', 'ConsumerResponse.content.reasonCode') | stats count by 'BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode'&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 09 Jul 2024 16:22:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692786#M235786</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-07-09T16:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692788#M235787</link>
      <description>&lt;P&gt;No luck &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sridharadurthi_0-1720542382140.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31656i3B14FEA42A7BEF54/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sridharadurthi_0-1720542382140.png" alt="sridharadurthi_0-1720542382140.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 16:26:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692788#M235787</guid>
      <dc:creator>sridharadurthi</dc:creator>
      <dc:date>2024-07-09T16:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692789#M235788</link>
      <description>&lt;P&gt;Please try it exactly as I showed you - I have already explained that you need double quotes to the left of the assignment and single quotes to the right - if you do not follow simple instructions like this, you will struggle to get a working solution!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 16:34:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692789#M235788</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-07-09T16:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692792#M235790</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;thanks for being patient with me. I have copied the same query which you have mentioned and this is the result&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sridharadurthi_0-1720543269927.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31657iEFF67D9BE65AB9EB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sridharadurthi_0-1720543269927.png" alt="sridharadurthi_0-1720543269927.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;LI-CODE lang="css"&gt;index="apigee" sourcetype!="apigee:nginx" (ProxyPath="/xyz" OR ProxyPath="/abc") AND StatusCode=200 | eval "BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode" = coalesce('BackendResponse.content.reasonCode', 'ConsumerResponse.content.reasonCode')
| stats count by 'BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 16:42:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692792#M235790</guid>
      <dc:creator>sridharadurthi</dc:creator>
      <dc:date>2024-07-09T16:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692794#M235791</link>
      <description>&lt;P&gt;OK try it with double quotes on the stats command (which is counter-intuitive!)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="apigee" (ProxyPath="/xyz" OR ProxyPath="/abc") AND StatusCode=200 | eval "BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode" = coalesce('BackendResponse.content.reasonCode', 'ConsumerResponse.content.reasonCode') | stats count by "BackendResponse.content.reasonCode OR ConsumerResponse.content.reasonCode"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 09 Jul 2024 16:50:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692794#M235791</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-07-09T16:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Extract from Multiple Fields and Consolidate using Stats Count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692797#M235793</link>
      <description>&lt;P&gt;Finally it is working now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Thank you so much. You made my day.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sridharadurthi_0-1720544170590.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31658i91F2E3E272E300A8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sridharadurthi_0-1720544170590.png" alt="sridharadurthi_0-1720544170590.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 16:56:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-from-Multiple-Fields-and-Consolidate-using-Stats-Count/m-p/692797#M235793</guid>
      <dc:creator>sridharadurthi</dc:creator>
      <dc:date>2024-07-09T16:56:20Z</dc:date>
    </item>
  </channel>
</rss>

