Splunk Search

Do I have to turn count and if on like we have to do with delete?

BITSIntern
Path Finder

Hi guys,

I am having some trouble trying to do a search. I want to do a search that involves the tools count and if but it keeps giving me an error like: Unknown search command 'count'. When I wanted to delete a few things from my index, I had to go to my access controls and turn on the delete command but when I went back I did not see anything about other command functions.

Am I doing something wrong or do I need to turn the tools on?

Please let me know!

Tags (4)
0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

count and if are not commands. Stats and eval are, and those use count and if.

so....

<your_search> | stats count by sourcetype

That will get you started.

http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

0 Karma

BITSIntern
Path Finder

Sorry I did not know there was a search manual.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese and ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...