Monitoring Splunk

Statistical Count from a lookup Table

zacksoft
Contributor

I have a look up csv file added, which looks like this,
The header contains subject names and student name, and then subsequent rows contain performances for each pupil

MATH ENGLISH NAME SCIENCE
good bad Timmy best
good good John better
better bad Alek good

good bad Priya good
beter best Arun best

The above table means Timmy is 'good' at MATH, 'bad' at ENGLISH and 'best' at SCIENCE.
SImilarly John is 'good' at MATH and ENGLISH and 'bad' at SCIENCE.
etc...

I want to know how many kids are good, bad and best at each subject.
in stats table and if possible in a visualization.

e.g. 3 kids are good at MATH(Timmy, JOHN , Priya)
2 kids are best at SCIENCE (Timmy, Arun)

My query starts like,
| inputlookup marks.csv
| stats ........

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Here you go

| inputlookup marks.csv
| table NAME *
| untable NAME subject grade
| chart count over subject by grade

View solution in original post

0 Karma

somesoni2
Revered Legend

Here you go

| inputlookup marks.csv
| table NAME *
| untable NAME subject grade
| chart count over subject by grade
0 Karma

koshyk
Super Champion

Is it something you looking for?

|inputlookup marks.csv
| stats values(NAME) as students, count by ENGLISH

if yes, you can expand to other subjects

0 Karma

zacksoft
Contributor

What are the subjects where the BEST count is less than 5 ?
i.e. What are those subjects' names where only 5 or less students perform as BEST.

0 Karma

zacksoft
Contributor

It is counting the header name too . How do I exclude that?
Also, I have a lot of subjects, more than 50, how can I see them all in one query ? Is it possible..

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...