Career Resources
Post your Splunk jobs. Get career tips!

count number of events for each client?

rhlb18
Observer

Hi Splunkers,

Typically , I am looking for a SPL query to get the names of each client, total error associated  with each client in it. I have used below query which returns the total number of events and total number of clients who are facing this issue. Could someone please help so that, I could further make Pie chart with it.

(index=prod-web) AND "Error looking for client=* invoicingEntityId='*'" | stats count as Total dc(cf_client) as Client

rhlb18_1-1614681174554.png

 

 

0 Karma

rhlb18
Observer

@KailA - Thank your help. But,  I am just thinking if we can count the event the number of invents and not the number of cf_client?

0 Karma

KailA
Contributor

Hello 🙂

You just to do a little modification in your search :

(index=prod-web) AND "Error looking for client=* invoicingEntityId='*'" 
| stats count as Total BY cf_client

 This should return the number of error by client.

Let me know if it helps you 🙂 

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...