Dashboards & Visualizations

How to count values based on another column result?

KalebeRS
Explorer

KalebeRS_1-1688647570022.png

Hello,
I have this dashboard with this 3 fields (ID, A1_Links, A2_Links).
The goal is to have the count of the total of ID's containing links, based on the A1 and A2 Links columns. (How many ID's containing A1 links and how many ID's containing A2 links)

How can I do that?

 

index="" host= sourcetype=csv source=CW27.csv
| dedup ID
| table ID A1_Links A2_Links

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @KalebeRS,

please try this:

index="your_index" host=your_host sourcetype=csv source=CW27.csv
| stats dc(ID) AS ID_count BY A1_Links A2_Links

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

What's New in Splunk Observability - July 2025

What’s New?  We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what ...