Splunk Search

Count with few eval and timechart

michalmartofel
Observer

Hi,

i have a problem with a few queries. I have something actually like this:

 

 

index = nsw_prod_eximee ERROR 
| rex field=formInstanceNumber (?<pref>\w{3})\d{9} 
| rex field=applicationNumber (?<pref>\w{3})\d{9} 
| eval "Name" = case(pref=="USP", "mProtection", pref=="FGT", "mTravel", pref=="FGH", "HouseHold", pref=="FGS", "mMoto") 
| stats count as formInstanceNumber by "Name" 
| rename formInstanceNumber as "Errors"

 

 

And i have a table with a 4 values:

michalmartofel_1-1626863691530.png

But now i have a problem to count a column "Errors". I want to count all Errors.

 

2. The second problem i have, i can't do the timechart and i need help with it. I want to do timechart with that all values, but when i do that, there is no columns on timechart. How to get that query?

 

Thanks in advance.

Labels (3)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What do you mean count errors - the sum of the values in the errors column or the number of rows?

For a timechart, you need a _time field - this is not carried forward by the stats command (unless you say that it should be, and in this case you might want to bin _time into spans of time before you do the stats).

0 Karma

michalmartofel
Observer

1. Yes, excatly, i need the sum of the values in the errors column.

2. About timechart.. Actually i have a timechart with one product with query:

index = nsw_prod_eximee ERROR | regex _raw="[F][G][S]\d{9}" | dedup formInstanceNumber | timechart count by dc(formInstanceNumber OR applicationNumber) where count in top99

But now i want to have all products which have different regex (FGS, FGH, FGT, USP) and different field to dedup (with FGS and FGH i need to dedup variable formInstanceNumber, for USP and FGT it's applicationNumber). 

For one product it's okey, but how to connect all that regexes with dedups in timechart. That's my question.

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...