Splunk Search

How to compare 5 different fields and get the count of their occurrence

aaa2324
Explorer

Hi Team,

I would like to compare below 5 different columns and get one more column as a count.

category code  text  country  org

abc           100      Adv    US          12

abc            100     Adv    US         12

abc             100     Agh    Eu           13

abc             100     Agh    Eu           13

Column count should have have the number of times of occurrence of the below, say first 2 entries are occurring 2 time so it should display the output as

category code  text  country  org   Count

abc           100      Adv    US          12       2

kindly help with the query to achieve this.

Labels (1)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@aaa2324 

try this.

 

YOUR_SEARCh | stats count by category code  text  country  org

 

Sample:

| makeresults | eval _raw="category	code	text	country	org
abc	100	Adv	US	12
abc	100	Adv	US	12
abc	100	Agh	Eu	13
abc	100	Agh	Eu	13"
| multikv forceheader=1
| table category code  text  country  org
| stats count by category code  text  country  org

 

0 Karma

aaa2324
Explorer

Thanks but this is giving me the results as count below.

abc     100     Adv    US   1

but I want the result to have count as 2 since it is occurring twice. 

kindly advise 

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Screenshot 2021-05-04 at 7.10.20 PM.png

 

 It's giving 2 as count. can you please share your sample search ?

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...