Splunk Search

Accessing Splunk pre-calculated fields

a_vobard
Explorer

Hello, is there a possibility to access these fields?

a_vobard_0-1627989893600.png

 

Thanks, Ava

Labels (1)
0 Karma
1 Solution

a_vobard
Explorer

Hello,

I solved it by accident. I used the "top" command, which automatically adds the count and the percentage to the table. So, solved.

View solution in original post

0 Karma

a_vobard
Explorer

Hello,

I solved it by accident. I used the "top" command, which automatically adds the count and the percentage to the table. So, solved.

View solution in original post

0 Karma

venkatasri
Influencer

Hi @a_vobard 

That's nothing but top command, you can try this

index=re | top linecount

 

--

an upvote would be appreciated and Accept solution if this reply helps!

0 Karma

a_vobard
Explorer

Hello,

the linecount is one of the numbers I need. What I need is actually such table:

a_vobard_1-1628077266364.png

The Numbers in red I am missing. So I need these numbers:

- Total errors

- Number of specific errors

- Percentage of specific errors

I searched in the internet for this because it seamed for me as something basic, but unfortunately didn't find the answers.

 

Another question: How do you save the linecount in an column, so that I can use it in a table.  Something like

| top linecount as Linecount...but this doesn't work....

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!