Deployment Architecture

How can I add the index to the fieldsummary as an extra column?

datitran
New Member

If I do index=* | fieldsummary I get the fieldsummary of all indices.
How can I add the index to the fieldsummary as an extra column, so that I will have:

index, field, count, distinct_count, ..., values

0 Karma
1 Solution

somesoni2
Revered Legend

Try this (slower performance)

| eventcount summary=f index=* | table index
| map maxsearch=1000 search="search index=$index$ | fieldsummary | eval index=\"$index$\""
| table index * 

OR

| rest /services/data/indexes | table title | dedup title 
| map maxsearch=1000 search="search index=$title$ | fieldsummary | eval index=\"$title$\""
| table index * 

View solution in original post

0 Karma

somesoni2
Revered Legend

Try this (slower performance)

| eventcount summary=f index=* | table index
| map maxsearch=1000 search="search index=$index$ | fieldsummary | eval index=\"$index$\""
| table index * 

OR

| rest /services/data/indexes | table title | dedup title 
| map maxsearch=1000 search="search index=$title$ | fieldsummary | eval index=\"$title$\""
| table index * 
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...