Splunk Search

Function results and evaluating them

rudy_dom
Engager

Soo - I got this great search to show how many hosts at each location we are getting logs from. I want to only display the ones that have less than 3 reporting in.
This is what I have so far:

host=host2 OR host=*host1 OR host=otherhost | rex field=host "(?\d{4})" | fields fruit host | stats distinct_count(host) by fruit | sort num(distinct_count(host))

I thought I could add this:
| eval (distinct_count(host)) < 3

But it does not work.
I guess I need to assign a key to the value derived from "stats distinct_count(host) by fruit" so I can use that key for the evaluation. where does not work either.

Rudy

Tags (3)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

So you tried this:

host=host2 OR host=host1 OR host=otherhost* | rex field=host "(?<fruit>d{4})" | fields fruit host | stats distinct_count(host) as myCount by fruit | sort -myCount

and then you could add

 where myCount < 3 or | search myCount < 3

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

So you tried this:

host=host2 OR host=host1 OR host=otherhost* | rex field=host "(?<fruit>d{4})" | fields fruit host | stats distinct_count(host) as myCount by fruit | sort -myCount

and then you could add

 where myCount < 3 or | search myCount < 3
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...