<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search to group by Country, City having count sorted for Country and City in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-to-group-by-Country-City-having-count-sorted-for-Country/m-p/183266#M52776</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I try to create stats to have all countries and cities that communicate with my servers.&lt;/P&gt;

&lt;P&gt;I made this search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="syslog" deviceVendor="Apache" | iplocation ipVisitor |  eval City= if(isnull(City) OR City="", "Unknown_City", City) | stats values(City) AS CityName, count by Country | sort - count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It give me in the first column the Country, then in the second column all cities in this country and in the last third column the total count.&lt;/P&gt;

&lt;P&gt;I would like to have such thing instead:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Country name   |   Cities Name (count) | Total Count
United States  |   New York (5)        |     10
               |   Boston (3)          |
               |   Washington (2)      |
 France        | Paris (10)            |     12
               |  Marseille (2)        |     2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I don't know how to do that to append the "(nbr)" to the City name&lt;/P&gt;</description>
    <pubDate>Wed, 11 Mar 2015 13:51:53 GMT</pubDate>
    <dc:creator>danje57</dc:creator>
    <dc:date>2015-03-11T13:51:53Z</dc:date>
    <item>
      <title>Search to group by Country, City having count sorted for Country and City</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-to-group-by-Country-City-having-count-sorted-for-Country/m-p/183266#M52776</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I try to create stats to have all countries and cities that communicate with my servers.&lt;/P&gt;

&lt;P&gt;I made this search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="syslog" deviceVendor="Apache" | iplocation ipVisitor |  eval City= if(isnull(City) OR City="", "Unknown_City", City) | stats values(City) AS CityName, count by Country | sort - count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It give me in the first column the Country, then in the second column all cities in this country and in the last third column the total count.&lt;/P&gt;

&lt;P&gt;I would like to have such thing instead:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Country name   |   Cities Name (count) | Total Count
United States  |   New York (5)        |     10
               |   Boston (3)          |
               |   Washington (2)      |
 France        | Paris (10)            |     12
               |  Marseille (2)        |     2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I don't know how to do that to append the "(nbr)" to the City name&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2015 13:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-to-group-by-Country-City-having-count-sorted-for-Country/m-p/183266#M52776</guid>
      <dc:creator>danje57</dc:creator>
      <dc:date>2015-03-11T13:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Search to group by Country, City having count sorted for Country and City</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-to-group-by-Country-City-having-count-sorted-for-Country/m-p/183267#M52777</link>
      <description>&lt;P&gt;i propose you to make multi-values fields for City and count. look how to use multi-values in search reference manual page 258&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2015 12:13:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-to-group-by-Country-City-having-count-sorted-for-Country/m-p/183267#M52777</guid>
      <dc:creator>tachifelix</dc:creator>
      <dc:date>2015-03-23T12:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Search to group by Country, City having count sorted for Country and City</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-to-group-by-Country-City-having-count-sorted-for-Country/m-p/183268#M52778</link>
      <description>&lt;P&gt;You mean using multikv?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2015 14:11:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-to-group-by-Country-City-having-count-sorted-for-Country/m-p/183268#M52778</guid>
      <dc:creator>danje57</dc:creator>
      <dc:date>2015-03-23T14:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Search to group by Country, City having count sorted for Country and City</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-to-group-by-Country-City-having-count-sorted-for-Country/m-p/183269#M52779</link>
      <description>&lt;P&gt;Here you go&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="syslog" deviceVendor="Apache" | iplocation ipVisitor |  eval City= if(isnull(City) OR City="", "Unknown_City", City) | stats count by Country,City | eval City=City."(".count.")" | stats values(City) as CityName, sum(count) as "Total Count" by Country
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 23 Mar 2015 18:00:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-to-group-by-Country-City-having-count-sorted-for-Country/m-p/183269#M52779</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-03-23T18:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: Search to group by Country, City having count sorted for Country and City</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-to-group-by-Country-City-having-count-sorted-for-Country/m-p/183270#M52780</link>
      <description>&lt;P&gt;Exactly that I need!&lt;/P&gt;

&lt;P&gt;Many thanks!!!!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2015 12:13:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-to-group-by-Country-City-having-count-sorted-for-Country/m-p/183270#M52780</guid>
      <dc:creator>danje57</dc:creator>
      <dc:date>2015-03-24T12:13:44Z</dc:date>
    </item>
  </channel>
</rss>

