Splunk Search

Finding count of grouped data

jimjohn
Path Finder

How can we find the distinct values inside a grouped values.

I use transaction to group data.Now i want to find count(filed2) for each grouped data.
host=A|transaction "field1"|stats count("field2") but not return the appropriate result.
Can anybody help.

0 Karma

kristian_kolb
Ultra Champion

Hi,

you might want to play with eventstats prior to the transaction, like so (used _internal index so that you can test the exact search);

index=_internal sourcetype=splunkd earliest=@d-1m latest=@d group=* 
| eventstats count(name) as bob 
| transaction group 
| stats first(bob)

In this case the final stats produces the same count as if it had been placed before the transaction (instead of eventstats).

Hope this helps,

/K

Please provide some more sample data, and a sketch of the desired results if this does not work.

Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...