Splunk Search

How can I group the query?

uppukumar
Explorer

Hi all,

I am new to splunk
Following is the information:

Column1                          Column2         column3
first                            Success
first                            Incomplete
First                           Timeout 

I want the above information like

Column1             successcount               Fail count
first                      1                         2

Note:Here Fail count is Incomplete and Timeout

Can any one help on this how to form a qeury to get the above output

Thanks

Tags (1)
0 Karma

renjith_nair
Legend

@uppukumar,

Try,

"your base search " 
| stats count(eval(Column2 ="Success")) as SuccessCount,count(eval(Column2 !="Success")) as FailedCount by Column1

You may change the condition for FailedCount based on your criteria

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

vnravikumar
Champion

Hi @uppukumar

Try like

your query..| stats count(eval(Coloumn2="Success")) as "Success count" count(eval(Coloumn2="Incomplete" OR Coloumn2="Timeout")) as "Fail count" by Coloumn1
0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...