- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to Count multiple fields in histogram?
rpecka
Explorer
06-27-2022
12:13 PM
I have rows in the form:
ID | Field1 | Field2 | Field3 |
And I would like to create a histogram that shows the values of all three fields.
I can make one for Field1 by doing stats count by Field1 span=1000 but I can't seem to figure out how I would get the other values into the same table. Do I need to do multiple searches and join them? How would I go about doing that?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ITWhisperer

SplunkTrust
07-01-2022
09:46 AM
It is not clear what you expect the result to look like - for example, if field1 contains either "A", "B", or "C", and field2 contains either "A", "B", or "C", do you want the frequency of "A" in field1 counted separately from the frequency of "A" in field2, etc.?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yuanliu

SplunkTrust
06-27-2022
11:34 PM
You can bin every field before counting, e.g.,
index=_internal
| bin date_hour
| bin date_minute
| bin date_second
| stats count by date_hour date_minute date_second
Would this work for your scenario?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gcusello

SplunkTrust
06-27-2022
11:47 PM
