Splunk Search

For loop on each result of a the table

giolapid911
New Member

I have query that  returns successful logins and a profile ID.

 

Then from the result of those I want to create another search for each result that shows the email address of the the profile ID.

 

First query is 

index=commerce loginSuccessful=true
| stats count by profile

giolapid911_0-1667594223270.png

 

Then I would want to do the following.

 

For each "profile"

index=commerce "profile email!="<null>" email!=null | table profile email 

 

Labels (1)
0 Karma

johnhuang
Motivator
index=commerce ((loginSuccessful=true) OR ("profile email!="<null>" AND email!=null))
| eval login_ct=CASE(loginSuccessful="true", 1)
| stats sum(login_ct) AS login_ct BY profile email
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...