Splunk Search

Counting Events?

MichaelCohen829
Explorer

Splunk Community,

I’d like to be able to count the number of events I have per SourceFile when my sourcetype is LogFile:

sourcetype="LogFile" SourceFile="File1”

I also have a number of other SourceFiles (“File2” , “File3” …etc…)

I’ve tried a number of things with no success as of yet – does anyone know how would I be able to count the number of events, per SourceFile within the SourceType “LogFile”?

Thank you,

Mike

Tags (2)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi MichaelCohen829,

try something like this:

sourcetype="LogFile" OR SourceFile="File*" | stats count by sourcetype

cheers, MuS

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Counting and filtering by metadata fields such as source and sourcetype can be done much more quickly with tstats:

| tstats count where index=yourindex sourcetype="LogFile" by source

http://docs.splunk.com/Documentation/Splunk/6.1.1/SearchReference/tstats

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi MichaelCohen829,

try something like this:

sourcetype="LogFile" OR SourceFile="File*" | stats count by sourcetype

cheers, MuS

MuS
SplunkTrust
SplunkTrust

Thanks, you're welcome

0 Karma

MichaelCohen829
Explorer

Thank you MuS - this achieved exactly what I wanted!

Mike

0 Karma
Get Updates on the Splunk Community!

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...