Splunk Search

Counting Events?

MichaelCohen829
Explorer

Splunk Community,

I’d like to be able to count the number of events I have per SourceFile when my sourcetype is LogFile:

sourcetype="LogFile" SourceFile="File1”

I also have a number of other SourceFiles (“File2” , “File3” …etc…)

I’ve tried a number of things with no success as of yet – does anyone know how would I be able to count the number of events, per SourceFile within the SourceType “LogFile”?

Thank you,

Mike

Tags (2)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi MichaelCohen829,

try something like this:

sourcetype="LogFile" OR SourceFile="File*" | stats count by sourcetype

cheers, MuS

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Counting and filtering by metadata fields such as source and sourcetype can be done much more quickly with tstats:

| tstats count where index=yourindex sourcetype="LogFile" by source

http://docs.splunk.com/Documentation/Splunk/6.1.1/SearchReference/tstats

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi MichaelCohen829,

try something like this:

sourcetype="LogFile" OR SourceFile="File*" | stats count by sourcetype

cheers, MuS

MuS
SplunkTrust
SplunkTrust

Thanks, you're welcome

0 Karma

MichaelCohen829
Explorer

Thank you MuS - this achieved exactly what I wanted!

Mike

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...