Splunk Search

How to compare multiple sourcetypes?

tonahoyos
Explorer

Hello,

In one index I have multiple sourcetypes. I want to be able to compare the values between these sourcetypes, but I do not know where to even start.

I was trying the following search:

index="log"
| stats count events if(sourcetype="SAT") as SAT

but this search seems very complicated. I want to be able to do something like:

|stats count events by sourcetype

but again, this doesn't work. Help!

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

If you're only interested in event count, you can use a rather efficient command tstats (works on metadata fields e.g. index/host/sourcetype/source etc which you seems to do)

To get a row for each sourcetype with count of events in selected time range

|tstats count WHERE index="log" by sourcetype         

To get a column for each sourcetype with count of events in selected time range

|tstats count WHERE index="log" by index sourcetype   | chart sum(count) by index sourcetype limit=0

View solution in original post

0 Karma

somesoni2
Revered Legend

If you're only interested in event count, you can use a rather efficient command tstats (works on metadata fields e.g. index/host/sourcetype/source etc which you seems to do)

To get a row for each sourcetype with count of events in selected time range

|tstats count WHERE index="log" by sourcetype         

To get a column for each sourcetype with count of events in selected time range

|tstats count WHERE index="log" by index sourcetype   | chart sum(count) by index sourcetype limit=0
0 Karma

tonahoyos
Explorer

Perfect! Thank you!

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...