Splunk Search

Count Command

sukhgillz
Explorer

Hi,

I'm experiencing some difficulties when using count, the below search query works by listing sip (source ip) against all the siganmes (signatures) which were triggered against the sip. I'm trying to break this down further with a count of these signatures, so:

sip signature count
1.1.1.1 UDP Flood 4
TCP Flood 56
2.2.2.2 UDP Flood 6
TCP Flood 34

I've constructed the following search:

idp-01 signame=* | transaction sip signame count by eventid | table sip signame |stats list(signame) by sip

eventid is a unique reference for each event, this gives me:

sip list(signature)
1.1.1.1 UDP Flood
UDP Flood
UDP Flood
TCP Flood
TCP Flood
TCP Flood
TCP Flood
[repeats 56 times]

Any clues where I’m going wrong here?

Thanks.

Tags (1)
0 Karma
1 Solution

gfuente
Motivator

hello

Try this:

...| stats count by sip, signature

View solution in original post

gfuente
Motivator

hello

Try this:

...| stats count by sip, signature

sukhgillz
Explorer

Thanks gfuente works a treat 😉

0 Karma

gfuente
Motivator

Try:
...| stats dc(eventid) by sip, signature

0 Karma

sukhgillz
Explorer

counting by sip, signame breaks the table with two columns sip and list(signature), with the sip detailing the source ip associated with the signatures triggered. I'm looking for a third column with a count of the number of times each signature was triggered. Each log has a unique field "eventid" so was looking at using this as a counter.

0 Karma

Ayn
Legend

What do you mean no joy - what are your results and how do they differ from the results you want?

0 Karma

sukhgillz
Explorer

Hi gfunete, no joy...
Thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...