Hi All,
I am new to SPLUNK and building dashboards and I have requirement to count the records from the table
So, any thoughts on it ?
Thanks in advance.
If you want to find a number of pending records then you should write
index="XXXXX" PRODUCT=100 STATUS="P" | stats dc(PCN) as "Pending"
Also if you want all the three requirements in one dashboard then you can try something like this
index="XXXXX" PRODUCT=100 | stats dc(PCN) by STATUS
let me know if this helps!