Splunk Search

How do I get total count of a field per host?

amit2312
Engager

Hi,

I am new to splunk, this might have asked and answered but didn't get the answer when i searched it. here is my query: I have a base query, which basically gets the ids field(ex : 1234,3213) from different hosts. i want to get the total number of ids per host. 

data:

host : ids: price: details

xyz:123:$45:example 

cds:143:$45:example

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Use the stats command for that.

| stats count(ids) by host

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

As @richgalloway but if you want unique ids, use dc(ids)

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Use the stats command for that.

| stats count(ids) by host

 

---
If this reply helps you, Karma would be appreciated.

amit2312
Engager

Thanks a lot for your help. it worked.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...