<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic stats count by variable field names? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/stats-count-by-variable-field-names/m-p/321884#M96161</link>
    <description>&lt;P&gt;I have a need to stats count by a list of variable fields that I don't know the names of.  (stats count by *  doesn't seem to work).  Does anyone have any ideas?&lt;/P&gt;

&lt;P&gt;I know I would need to fillnull the empty fields then stats count by (list of all fields).  This is a reduced set already so I'm not actually fill nulling.    &lt;/P&gt;</description>
    <pubDate>Wed, 22 Feb 2017 01:03:28 GMT</pubDate>
    <dc:creator>the_wolverine</dc:creator>
    <dc:date>2017-02-22T01:03:28Z</dc:date>
    <item>
      <title>stats count by variable field names?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-count-by-variable-field-names/m-p/321884#M96161</link>
      <description>&lt;P&gt;I have a need to stats count by a list of variable fields that I don't know the names of.  (stats count by *  doesn't seem to work).  Does anyone have any ideas?&lt;/P&gt;

&lt;P&gt;I know I would need to fillnull the empty fields then stats count by (list of all fields).  This is a reduced set already so I'm not actually fill nulling.    &lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 01:03:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-count-by-variable-field-names/m-p/321884#M96161</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2017-02-22T01:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: stats count by variable field names?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-count-by-variable-field-names/m-p/321885#M96162</link>
      <description>&lt;P&gt;How about &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; stats count(*) by *
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;?  I forget if that's he workaround or not been a moment for me.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2017 02:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-count-by-variable-field-names/m-p/321885#M96162</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-02-22T02:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: stats count by variable field names?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/stats-count-by-variable-field-names/m-p/321886#M96163</link>
      <description>&lt;P&gt;I am taking you VERY literally so it is quite possible that this is not what you are really seeking.  In order for this solution to work, you need 1 "real" field that you need to keep; I will assume that &lt;CODE&gt;host&lt;/CODE&gt; is that field for you..  If there are more fields, then you will have to combine them so that you only have 1.  For example, if you would like to keep &lt;CODE&gt;sourcetype&lt;/CODE&gt;, too, then do this first (and use &lt;CODE&gt;host_sourcetype&lt;/CODE&gt; instead of &lt;CODE&gt;host&lt;/CODE&gt; in the last search):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval host_sourcetype = host . "::" . sourcetype | fields - host sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now that you only have 1 "keeper" field and then the "various" fields (make sure that you get rid of any other fields by using &lt;CODE&gt;fields - list of other fields here&lt;/CODE&gt;), you do this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| untable host various value
| stats sum(*) count(*) list(*) by host various
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 22 Feb 2017 03:57:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/stats-count-by-variable-field-names/m-p/321886#M96163</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-02-22T03:57:36Z</dc:date>
    </item>
  </channel>
</rss>

