Splunk Enterprise Security

How to use tstats command with datamodel and like function

N92
Path Finder

How to use tstats command with like function.
Ex:

| tstats count(eval(Authentication.action, "failure%")) as failure,  count(eval(Authentication.action, "success%"))  as success by src

Why does it give an error?

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

tstats does not support complex aggregation function. ref. doc https://docs.splunk.com/Documentation/Splunk/7.2.6/SearchReference/Tstats#Complex_aggregate_function...

So you can use below query

| tstats count from datamodel=Authentication by Authentication.src,Authentication.action
| stats sum(eval(if(like('Authentication.action', "failure%"),count,0))) as failure sum(eval(if(like('Authentication.action', "success%"),count,0))) as success by Authentication.src

View solution in original post

harsmarvania57
Ultra Champion

Hi,

tstats does not support complex aggregation function. ref. doc https://docs.splunk.com/Documentation/Splunk/7.2.6/SearchReference/Tstats#Complex_aggregate_function...

So you can use below query

| tstats count from datamodel=Authentication by Authentication.src,Authentication.action
| stats sum(eval(if(like('Authentication.action', "failure%"),count,0))) as failure sum(eval(if(like('Authentication.action', "success%"),count,0))) as success by Authentication.src
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...