Deployment Architecture

How can I add the index to the fieldsummary as an extra column?

datitran
New Member

If I do index=* | fieldsummary I get the fieldsummary of all indices.
How can I add the index to the fieldsummary as an extra column, so that I will have:

index, field, count, distinct_count, ..., values

0 Karma
1 Solution

somesoni2
Revered Legend

Try this (slower performance)

| eventcount summary=f index=* | table index
| map maxsearch=1000 search="search index=$index$ | fieldsummary | eval index=\"$index$\""
| table index * 

OR

| rest /services/data/indexes | table title | dedup title 
| map maxsearch=1000 search="search index=$title$ | fieldsummary | eval index=\"$title$\""
| table index * 

View solution in original post

0 Karma

somesoni2
Revered Legend

Try this (slower performance)

| eventcount summary=f index=* | table index
| map maxsearch=1000 search="search index=$index$ | fieldsummary | eval index=\"$index$\""
| table index * 

OR

| rest /services/data/indexes | table title | dedup title 
| map maxsearch=1000 search="search index=$title$ | fieldsummary | eval index=\"$title$\""
| table index * 
0 Karma
Get Updates on the Splunk Community!

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...

New Splunk APM Enhancements Help Troubleshoot Your MySQL and NoSQL Databases Faster

Splunk Observability has two new enhancements to make it quicker and easier to troubleshoot slow or frequently ...