Splunk Search

Help on weblog parsing

pbenner
Explorer

I need to aggregate the values found in the apache weblogs. First I need to parse out several fields. I can get these fileds parsed out. But now I need to aggregate the counts of these fields. For example, the number of elements requested per client over a selected time range. So I need to count all the elements for each client and display them in a graph. And also show in descending order the clients that requested an element. Is this doable? If so what components do I use?

0 Karma
1 Solution

Lowell
Super Champion

Yes. This is very doable.

I would recommend checking out the following search commands to get started:

  • stats
  • chart
  • timechart

If you are pretty new to splunk. Check out How search commands work and go from there. There is also a basic search tutorial that is very helpful in walking though basic commands too.

View solution in original post

Lowell
Super Champion

Yes. This is very doable.

I would recommend checking out the following search commands to get started:

  • stats
  • chart
  • timechart

If you are pretty new to splunk. Check out How search commands work and go from there. There is also a basic search tutorial that is very helpful in walking though basic commands too.

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...