Splunk Search

Function results and evaluating them

rudy_dom
Engager

Soo - I got this great search to show how many hosts at each location we are getting logs from. I want to only display the ones that have less than 3 reporting in.
This is what I have so far:

host=host2 OR host=*host1 OR host=otherhost | rex field=host "(?\d{4})" | fields fruit host | stats distinct_count(host) by fruit | sort num(distinct_count(host))

I thought I could add this:
| eval (distinct_count(host)) < 3

But it does not work.
I guess I need to assign a key to the value derived from "stats distinct_count(host) by fruit" so I can use that key for the evaluation. where does not work either.

Rudy

Tags (3)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

So you tried this:

host=host2 OR host=host1 OR host=otherhost* | rex field=host "(?<fruit>d{4})" | fields fruit host | stats distinct_count(host) as myCount by fruit | sort -myCount

and then you could add

 where myCount < 3 or | search myCount < 3

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

So you tried this:

host=host2 OR host=host1 OR host=otherhost* | rex field=host "(?<fruit>d{4})" | fields fruit host | stats distinct_count(host) as myCount by fruit | sort -myCount

and then you could add

 where myCount < 3 or | search myCount < 3
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...