Splunk Search

Accessing Splunk pre-calculated fields

a_vobard
Explorer

Hello, is there a possibility to access these fields?

a_vobard_0-1627989893600.png

 

Thanks, Ava

Labels (1)
0 Karma
1 Solution

a_vobard
Explorer

Hello,

I solved it by accident. I used the "top" command, which automatically adds the count and the percentage to the table. So, solved.

View solution in original post

0 Karma

a_vobard
Explorer

Hello,

I solved it by accident. I used the "top" command, which automatically adds the count and the percentage to the table. So, solved.

0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @a_vobard 

That's nothing but top command, you can try this

index=re | top linecount

 

--

an upvote would be appreciated and Accept solution if this reply helps!

0 Karma

a_vobard
Explorer

Hello,

the linecount is one of the numbers I need. What I need is actually such table:

a_vobard_1-1628077266364.png

The Numbers in red I am missing. So I need these numbers:

- Total errors

- Number of specific errors

- Percentage of specific errors

I searched in the internet for this because it seamed for me as something basic, but unfortunately didn't find the answers.

 

Another question: How do you save the linecount in an column, so that I can use it in a table.  Something like

| top linecount as Linecount...but this doesn't work....

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...