Splunk Search

For loop on each result of a the table

giolapid911
New Member

I have query that  returns successful logins and a profile ID.

 

Then from the result of those I want to create another search for each result that shows the email address of the the profile ID.

 

First query is 

index=commerce loginSuccessful=true
| stats count by profile

giolapid911_0-1667594223270.png

 

Then I would want to do the following.

 

For each "profile"

index=commerce "profile email!="<null>" email!=null | table profile email 

 

Labels (1)
0 Karma

johnhuang
Motivator
index=commerce ((loginSuccessful=true) OR ("profile email!="<null>" AND email!=null))
| eval login_ct=CASE(loginSuccessful="true", 1)
| stats sum(login_ct) AS login_ct BY profile email
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...