Splunk Search

Finding count of grouped data

jimjohn
Path Finder

How can we find the distinct values inside a grouped values.

I use transaction to group data.Now i want to find count(filed2) for each grouped data.
host=A|transaction "field1"|stats count("field2") but not return the appropriate result.
Can anybody help.

0 Karma

kristian_kolb
Ultra Champion

Hi,

you might want to play with eventstats prior to the transaction, like so (used _internal index so that you can test the exact search);

index=_internal sourcetype=splunkd earliest=@d-1m latest=@d group=* 
| eventstats count(name) as bob 
| transaction group 
| stats first(bob)

In this case the final stats produces the same count as if it had been placed before the transaction (instead of eventstats).

Hope this helps,

/K

Please provide some more sample data, and a sketch of the desired results if this does not work.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...