Splunk Search

How do I iterate through a result set and fetch the data for each result?

Anantha123
Communicator

I have a query to retrieve "Item_Number " in table. The results will be as below...

..| table Item_Number 

Item_Number
1234
2345
4567

Now, I want to calculate count for each of these "Item Number " .

I used below query to get the count .

|table Item_Number |  map search="search index=* $Item_Number$|stats count as cnt" 

but I am getting zero results .

Please suggest how to achieve this count for each result values of "Item_Number "

Thanks in Advance.

Tags (2)
0 Karma

arkadyz1
Builder

Count of all instances of each value? If yes, try | stats count by Item_Number instead of table. stats generates values in such a way that you can use this search to power a table on a form/dashboard.

0 Karma

Vijeta
Influencer

try using

\"$Item_Number$\" instead of $Item_Number$

0 Karma

Anantha123
Communicator

Thanks for quick reply Vijeta, but its not working. I am still getting count 0's .

0 Karma

Anantha123
Communicator

my query worked when I gave $$Item_Number$$..
your answer "\"$Item_Number$\"" also helped me when i had to use with eval ..like |eval ItemNo=\"$Item_Number$\"| ..
Thank you so much Vijeta.
Sorry for late reply.

0 Karma

Vijeta
Influencer

No problem. Glad it worked!

0 Karma

Vijeta
Influencer

@ananthan123 can you please accept the answer .

0 Karma

Vijeta
Influencer

try using fields instead of table in main search

0 Karma

Anantha123
Communicator

Yeah Vijeta, I even tried with fields and used the syntax that you shared . But did not helped me getting the count .

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...