Splunk Search
Highlighted

Chart and table of occurences of field by another field

Path Finder

Hi

I would like to have some chart ( bar etc.) and table of logs which contain two information titleID and userID.
I would like to have table and chart of each user and sum of each titleID for him.

I'm using this search, but I'm not sure about it:

... | top "data.titleID" by "data.userID" | table "data.userID" "data.titleID" count

0 Karma
Highlighted

Re: Chart and table of occurences of field by another field

Legend

Hi swdowiarz,
hi did you already tried with

your_search
| stats sum(titleID) AS titleID BY userID
|  sort -titleID

?
if in addition you like to have only the first 10 top values you can add tho the above search | head 10

Bye.
Giuseppe

0 Karma
Highlighted

Re: Chart and table of occurences of field by another field

Path Finder

Hi

I don't know why but SUM(titleID) does not work for me, I don't know why

0 Karma
Highlighted

Re: Chart and table of occurences of field by another field

Legend

Are you sure that titleID is a number?
Byte.
Giuseppe

0 Karma
Highlighted

Re: Chart and table of occurences of field by another field

Path Finder

No it's not a number, sorry that I didn't specify it properly, "data.titleID" is some string and I would like to have stats of how many times each user has used each data.titleID

0 Karma
Highlighted

Re: Chart and table of occurences of field by another field

Legend

in this case you can use dc("data.titleID") AS "data.titleID"
Bye.
Giuseppe

0 Karma
Highlighted

Re: Chart and table of occurences of field by another field

Path Finder

I have the following issue:
Search Factory: Unknown search command 'dc'.

0 Karma
Highlighted

Re: Chart and table of occurences of field by another field

SplunkTrust
SplunkTrust

what is your fieldname titleID or data.titleID?

0 Karma
Highlighted

Re: Chart and table of occurences of field by another field

Path Finder

oh yes, because my log contains field data which contains titleID and orderID so to get them it's data.titleID and data.orderID

0 Karma
Highlighted

Re: Chart and table of occurences of field by another field

SplunkTrust
SplunkTrust

According to the comments, I think you want something like this

| stats count by data.userID data.titleID | sort- count

So this query will give you the stats of how many times each data.userID has used each data.titleID.

let me know if this helps!

View solution in original post

0 Karma