Splunk Community,
I’d like to be able to count the number of events I have per SourceFile when my sourcetype is LogFile:
sourcetype="LogFile" SourceFile="File1”
I also have a number of other SourceFiles (“File2” , “File3” …etc…)
I’ve tried a number of things with no success as of yet – does anyone know how would I be able to count the number of events, per SourceFile within the SourceType “LogFile”?
Thank you,
Mike
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Hi MichaelCohen829,
try something like this:
sourcetype="LogFile" OR SourceFile="File*" | stats count by sourcetype
cheers, MuS
 
		
		
		
		
		
	
			
		
		
			
					
		Counting and filtering by metadata fields such as source and sourcetype can be done much more quickly with tstats:
| tstats count where index=yourindex sourcetype="LogFile" by source
http://docs.splunk.com/Documentation/Splunk/6.1.1/SearchReference/tstats
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Hi MichaelCohen829,
try something like this:
sourcetype="LogFile" OR SourceFile="File*" | stats count by sourcetype
cheers, MuS
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Thanks, you're welcome
Thank you MuS - this achieved exactly what I wanted!
Mike
