Splunk Search

1. Total purchase split by product ID

dilip7504
New Member

please provide me solution on tutorial data

Client purchase details:
Provide details about client purchase details
1. Total purchase split by product ID
2. Total Products split by product ID

Tags (1)
0 Karma

renjith_nair
Legend

Hi @dilip7504,

In general, you could get it by ,

your search terms | stats coun(purchase) as Total_Purchase,count(Products) as Total_Products by product_id    

If this doesn't work , please provide some sample events

Happy Splunking!
0 Karma

dilip7504
New Member

doesn't work

sourcetype=access_* | stats count(purchase) as Total_Purchase,count(Products) as Total_Products by product_id

this is work

sourcetype=access_* action="purchase"| stats count as product by productId

0 Karma

renjith_nair
Legend

OK . Do you have any pending issues?

If you are experimenting with the tutorial data , then this might help https://www.splunk.com/en_us/resources/video.gzdGVpbzqfsrZ6zSHd2qbGhuXBhMrEME.html

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...