Splunk Search

Adding two stat results using one common field

husainpatanwala
Engager

Hi guys I have two stats

index |Exception| count

index |Error |count

I want is something like this :

index |Exception|Error |count .

count should be shown for exceptions where it is present for an index and same for Error.

something like this

 

index                 Exception                                   Error              count

index_1           ArithmeticException                                         50

index_2                                                                   loginerror         2

index_1                                                                   inputerror        5

the count shouldnt mess up due to same index.Please help !

 

Labels (5)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try this

search
| stats count by index exception
| append [
   search
  | stats count by index error
  ]

husainpatanwala
Engager

thanks mate,this one seems to be working.

0 Karma

tscroggins
Champion

@husainpatanwala 

stats omits output with null values in the by clause. The simplest way to achieve your desired output where count is greater than zero is to assign empty string values to Exception and Error when they're null:

| eval Exception=coalesce(Exception, ""), Error=coalesce(Error, "")
| stats count by index Exception Error

The coalesce() eval function is similar to the SQL COALESCE() function and returns the first non-null value in the argument list.

To include Exception and Error values where count is zero, you'll need to define a list of known Exception and Error values, append the list to your output, sort the list by descending count values, and deduplicate the Exception and Error output. Is this your intent?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...