Splunk Search

Can I count lines in table cell?

yossefn
Path Finder

Hi,

I have a search to show the number of times an IP address was trying to reach some Customer IDs.
How can I count the number of CustIds and present just if there are more than 2 in a cell?

Attached the search and results:

original search
| stats count by CustId, IpAddress
| search count>10
| sort -count
| stats list(CustId) as CustId, list(count) as Count, sum(count) as Total by IpAddress
| sort -Total
| head 10


IpAddress            CustId Count   Total
62.90.19.22           306352113 84  84

84.28.28.232          60555283   70 84
                      23070955   14

141.26.208.180      32370266     42 73
                      205539923 31
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Use mvcount.

| stats count by CustId, IpAddress
| search count>10
| stats list(CustId) as CustId, list(count) as Count, sum(count) as Total by IpAddress
| where mvcount(CustId) > 1
| sort 10 - Total
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Use mvcount.

| stats count by CustId, IpAddress
| search count>10
| stats list(CustId) as CustId, list(count) as Count, sum(count) as Total by IpAddress
| where mvcount(CustId) > 1
| sort 10 - Total
---
If this reply helps you, Karma would be appreciated.

yossefn
Path Finder

Working great, thank you!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...