Splunk Search

How to count and chart how many times a keyword showed in the log?

PatrickAlexande
New Member

Hi Friends,
How can I count and chart from a data source based on some keywords ?
example:
the log has THREAD_1, THREAD_2, THREAD_3 in the context and I need to be able to chart how many times each of these occurred!
and then build a chart to compare these three sets over the datetime

Thanks in advance,
Patrick

Tags (2)
0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Are the words you are looking for actual values of the same field, i.e. do they appear in the same position in the log? If so, why can't you extract the word values as a field and do a ** | stats count by word**?

Maybe providing a set of sample log events would help provide a better answer...

0 Karma

ppablo
Retired

Hi @PatrickAlexander

Here's a previous Answers post that might be able to point you in the right direction and it references an older post where the idea came from:
http://answers.splunk.com/answers/206552/how-can-i-calculate-the-term-frequency-for-all-the.html

0 Karma

PatrickAlexande
New Member

thank you for your post, but I cant find my answer within those !
I need to be able to count the words that I'm specifying with my search, I need to be able to count "THREAD_1", "THREAD_2", "THREAD_3" words and how many times they appear!

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...