Splunk Search

How do you use an aggregated value as a filter?

ygaluzo
New Member

Hello,

I need to use an aggregated value as a filter.

The search returns multiple rows, and I need only those with count > 30.

index=*production*  ERROR AND NOT DEBUG | eval svc=mvindex(split(index,"-"),4) | eventstats count as TOTAL_COUNT | stats latest(TOTAL_COUNT) as TC count by svc

Please kept.

Thank you

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@ygaluzo

Can you please try this?

index=*production* ERROR AND NOT DEBUG 
| eval svc=mvindex(split(index,"-"),4) 
| stats count as TC count by svc  | where TC > 30
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...