Dashboards & Visualizations

Splunk Query

bapun18
Communicator

Hi ,

Below is the existing query but when i run this for a single index  with its fields i get the  statistics data & count but when  i am trying to run all these 4 -indexes and it's respective fields together i am not  getting any Statistical table as output what changes do i need to make to list out all 4 indexes with their respective count in statistics. ..(For single index and it's fields it's working fine but when i try to merge all 4 index details it's statistics value is 0 as you can see below.)

bapun18_0-1598459013104.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You should use (index....) OR (index....) ... otherwise your logic could be wron as you have ORs and ANDs in your base query.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...

Splunk SOAR Now Available on Google Cloud Platform

We’re excited to announce that Splunk SOAR is now natively available as a SaaS solution on Google Cloud ...