Getting Data In

How do I individual count each of them in this path?

thiruyadav17
Engager


So, I wanted to Split the path into multiple events so that i can count whatever i want to count like active or dev or usa or etc.

We have few path i.e below

path=/dev/site/usa/active

path=/prod/site/usa/inactive

path=/dev/site/Germany/cleaning

path=/qa/site/Austria/maintenancemode

 

So now i want to count each of active by usa, dev
then I want to get the top 5 counts of it.

In the results i want to see the bar graph like
active 
cleaning 

maintenancemode

instead of whole path. 

Note: I don't have backend access. 

Labels (1)
Tags (3)
0 Karma

somesoni2
Revered Legend

 

 

Assuming the format of "path" including location of segments is static, you can extract each segment as separate field, like this

 

your current search which fetch field path
| rex field=path "\/(?<env>[^\/]+)\/site\/(?<country>[^\/]+)\/(?<status>[^\/]+)"

 

 

And then run your aggregation per your requirement

your current search which fetch field path
| rex field=path "\/(?<env>[^\/]+)\/site\/(?<country>[^\/]+)\/(?<status>[^\/]+)"
| stats count by env country status
| where country="usa" AND env="dev" AND status="active"
| sort 5 -count

ITWhisperer
SplunkTrust
SplunkTrust
| eval part=split(path,"/")
| stats count by part
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...