All Apps and Add-ons

How to search for a value in stats table?

mgubser
Explorer

I am getting the relevant data from multiple events and combining it in stats by device. I created the dashboard I wanted but I am now working on the drill down. I am unsure how to search for a value in this stats table i have created. I need to be able to look for the exact string, any string, as well as no string. I am aware of using eval and like but that creates a field that returns 1 or 0 and seems too long and inefficient when searching for multiple fields on one search.

0 Karma
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

really just putting an answer here because it keeps popping up in a filter...
1) this hasn't anything to do with Add-on for Nessus
2) I believe this is the best answer http://blogs.splunk.com/2014/04/01/search-command-stats-eventstats-and-streamstats-2/ -- but it might be simpler to use a map or subsearch? The way I've learned is to gather all the data together in the leftmost portions of your search and then tabulate.

View solution in original post

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

really just putting an answer here because it keeps popping up in a filter...
1) this hasn't anything to do with Add-on for Nessus
2) I believe this is the best answer http://blogs.splunk.com/2014/04/01/search-command-stats-eventstats-and-streamstats-2/ -- but it might be simpler to use a map or subsearch? The way I've learned is to gather all the data together in the leftmost portions of your search and then tabulate.

0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...