Splunk Search

1. Total purchase split by product ID

dilip7504
New Member

please provide me solution on tutorial data

Client purchase details:
Provide details about client purchase details
1. Total purchase split by product ID
2. Total Products split by product ID

Tags (1)
0 Karma

renjith_nair
Legend

Hi @dilip7504,

In general, you could get it by ,

your search terms | stats coun(purchase) as Total_Purchase,count(Products) as Total_Products by product_id    

If this doesn't work , please provide some sample events

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

dilip7504
New Member

doesn't work

sourcetype=access_* | stats count(purchase) as Total_Purchase,count(Products) as Total_Products by product_id

this is work

sourcetype=access_* action="purchase"| stats count as product by productId

0 Karma

renjith_nair
Legend

OK . Do you have any pending issues?

If you are experimenting with the tutorial data , then this might help https://www.splunk.com/en_us/resources/video.gzdGVpbzqfsrZ6zSHd2qbGhuXBhMrEME.html

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...