Splunk Search

For loop on each result of a the table

giolapid911
New Member

I have query that  returns successful logins and a profile ID.

 

Then from the result of those I want to create another search for each result that shows the email address of the the profile ID.

 

First query is 

index=commerce loginSuccessful=true
| stats count by profile

giolapid911_0-1667594223270.png

 

Then I would want to do the following.

 

For each "profile"

index=commerce "profile email!="<null>" email!=null | table profile email 

 

Labels (1)
0 Karma

johnhuang
Motivator
index=commerce ((loginSuccessful=true) OR ("profile email!="<null>" AND email!=null))
| eval login_ct=CASE(loginSuccessful="true", 1)
| stats sum(login_ct) AS login_ct BY profile email
0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...