Splunk Search

How do i get a count of each value of a field, and then extract the values whose count matches a certain number

ezmo1982
Path Finder

Hi,

I have the below SPL which gets the count of each value of the field named "subject". I want to be able to select the values whose count is greater than 5. For example, if the search below returned 10 results, but only 2 had a count greater than 5, how can I pick those two values out and store them in new fields that i can reference after. 

index=email_log RejType="Virus Signature Detection" | stats count by subject

Thanks!

Labels (2)
Tags (4)
1 Solution

peter_krammer
Communicator

So you want to filter to only the subjects that have a count greater than 5? 

index=email_log RejType="Virus Signature Detection"
| stats count by subject
| where count>5

View solution in original post

ezmo1982
Path Finder

Actually there was no need for me to store the values in a new field. Thanks

0 Karma

peter_krammer
Communicator

So you want to filter to only the subjects that have a count greater than 5? 

index=email_log RejType="Virus Signature Detection"
| stats count by subject
| where count>5

somesoni2
SplunkTrust
SplunkTrust

@ezmo1982 , Above search should give you first half or your requirement (filtering fields values whose count>5). For 2nd requirement (saving to a new field), please provide more information on what you intend to do with these values. 

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...