Splunk Search

Asterisk queue_log report on splunk

satishp
Explorer

Following is my asterisk queue_logs, I want to create chart base on Agent/72XX like home many users completed call something like that how do i filter and count numer of gents

1296490205|1296489840.5677|queue2|Agent/7211|COMPLETECALLER|7|48 1296489926|1296489840.5677|queue2|Agent/7210|CONNECT|3 1296489913|1296488593.5663|queue1|Agent/7217|COMPLETECALLER|6|1284 1296488629|1296488593.5663|queue1|Agent/7212|COMPLETECALLER|3|23 1296487993|1296487889.5652|queue1|Agent/7217|TRANSFER|7187 1296487821|1296487820.5651|NONE|Agent/7207|AGENTCALLBACKLOGIN|7217@queueagents

How to write search on splunk ?

Tags (1)
0 Karma

woodcock
Esteemed Legend

I think this is what you are asking (assuming that the 4th field is called user and the 5th is called action:disappointed_face:

... | stats dc(user) by action
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...