<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the difference between Event Count and Statistic Count in Splunk search results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-difference-between-Event-Count-and-Statistic-Count/m-p/199311#M57705</link>
    <description>&lt;P&gt;Upload the image to some third party website and provide the link.&lt;/P&gt;

&lt;P&gt;I guess you are asking about the Events and Statistics tabs of Search Assistant. Assuming this, i will answer your question.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Sep 2014 17:20:43 GMT</pubDate>
    <dc:creator>strive</dc:creator>
    <dc:date>2014-09-02T17:20:43Z</dc:date>
    <item>
      <title>What is the difference between Event Count and Statistic Count in Splunk search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-difference-between-Event-Count-and-Statistic-Count/m-p/199310#M57704</link>
      <description>&lt;P&gt;In Splunk search results, what is the difference between events count and statistic count. (I am unable to upload the image of the search result as my karma scoreis less than 60.)&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2014 16:12:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-difference-between-Event-Count-and-Statistic-Count/m-p/199310#M57704</guid>
      <dc:creator>sarfaraz1089</dc:creator>
      <dc:date>2014-09-02T16:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between Event Count and Statistic Count in Splunk search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-difference-between-Event-Count-and-Statistic-Count/m-p/199311#M57705</link>
      <description>&lt;P&gt;Upload the image to some third party website and provide the link.&lt;/P&gt;

&lt;P&gt;I guess you are asking about the Events and Statistics tabs of Search Assistant. Assuming this, i will answer your question.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2014 17:20:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-difference-between-Event-Count-and-Statistic-Count/m-p/199311#M57705</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-09-02T17:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between Event Count and Statistic Count in Splunk search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-is-the-difference-between-Event-Count-and-Statistic-Count/m-p/199312#M57706</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Events tab:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
It displays the plain events present in the index.&lt;BR /&gt;&lt;BR /&gt;
For Example: Say you write a search as &lt;CODE&gt;index=myindex earliest=-1d@d latest=-0d@d&lt;/CODE&gt; For this, the Events Tab lists all the events present in the index &lt;CODE&gt;myindex&lt;/CODE&gt; for previous day.&lt;BR /&gt;&lt;BR /&gt;
Note: Here &lt;CODE&gt;myindex&lt;/CODE&gt; can be a raw index or a summary index.&lt;BR /&gt;&lt;BR /&gt;
For the above search, the &lt;EM&gt;Statistics&lt;/EM&gt; tab doesn't display any reporting data since you have not used any reporting commands. The &lt;EM&gt;Statistics&lt;/EM&gt; tab will contain a message: &lt;CODE&gt;"Your search isn't generating any statistic or visualization results. Here are some possible ways to get results."&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Statistics tab:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
This tab depicts search results as report result tables. For the same search that is used in the &lt;EM&gt;Events&lt;/EM&gt; tab example, if we add some reporting search command, say for example: &lt;CODE&gt;index=myindex earliest=-1d@d latest=-0d@d | stats count as Count by ClientIP&lt;/CODE&gt; then the &lt;EM&gt;Statistics&lt;/EM&gt; tab contains data for this search with two columns ClientIP and Count.&lt;/P&gt;

&lt;P&gt;Assume that your index has 1000 log events and the unique ClientIP count in those 1000 log lines is 10. Then the &lt;EM&gt;Events&lt;/EM&gt; tab will contain 1000 entries and the tab heading will be &lt;CODE&gt;Events(1000)&lt;/CODE&gt;, the &lt;EM&gt;Statistics&lt;/EM&gt; tab will contain 10 entries and the tab heading will be &lt;CODE&gt;Statistics(10)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;One more point is: whether data gets displayed under &lt;EM&gt;Events&lt;/EM&gt; tab or not depends on the search mode.&lt;BR /&gt;
For more details read this &lt;A href="http://"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/Search/Changethesearchmode&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2014 17:35:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-is-the-difference-between-Event-Count-and-Statistic-Count/m-p/199312#M57706</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-09-02T17:35:48Z</dc:date>
    </item>
  </channel>
</rss>

