Monitoring Splunk

Statistical Count from a lookup Table

zacksoft
Contributor

I have a look up csv file added, which looks like this,
The header contains subject names and student name, and then subsequent rows contain performances for each pupil

MATH ENGLISH NAME SCIENCE
good bad Timmy best
good good John better
better bad Alek good

good bad Priya good
beter best Arun best

The above table means Timmy is 'good' at MATH, 'bad' at ENGLISH and 'best' at SCIENCE.
SImilarly John is 'good' at MATH and ENGLISH and 'bad' at SCIENCE.
etc...

I want to know how many kids are good, bad and best at each subject.
in stats table and if possible in a visualization.

e.g. 3 kids are good at MATH(Timmy, JOHN , Priya)
2 kids are best at SCIENCE (Timmy, Arun)

My query starts like,
| inputlookup marks.csv
| stats ........

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Here you go

| inputlookup marks.csv
| table NAME *
| untable NAME subject grade
| chart count over subject by grade

View solution in original post

0 Karma

somesoni2
Revered Legend

Here you go

| inputlookup marks.csv
| table NAME *
| untable NAME subject grade
| chart count over subject by grade
0 Karma

koshyk
Super Champion

Is it something you looking for?

|inputlookup marks.csv
| stats values(NAME) as students, count by ENGLISH

if yes, you can expand to other subjects

0 Karma

zacksoft
Contributor

What are the subjects where the BEST count is less than 5 ?
i.e. What are those subjects' names where only 5 or less students perform as BEST.

0 Karma

zacksoft
Contributor

It is counting the header name too . How do I exclude that?
Also, I have a lot of subjects, more than 50, how can I see them all in one query ? Is it possible..

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...