Splunk Search

How to count one field multiple times with different condition?

rj12
Loves-to-Learn Lots

Since I am new to Splunk is there is demo query for calculating this will be helpful,Basically, i want to count one field multiple times with the different condition

Tags (2)
0 Karma

adonio
Ultra Champion

lets imagine you have a field called fruit and it has 3 unique values apple,banana,mango
you can do this:
... search for your fruit field ... | stats count by fruit
you can also do this:
... search for your fruit field ... | stats count(eval(fruit="apple") as apples count(eval(fruit="banana")) as bananas count(eval(fruit="mango")) as mangos ....

read here more:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Search/Usetheevalcommandandfunctions#Example_1:_U....

note, there are other ways too

0 Karma
Get Updates on the Splunk Community!

Notification Email Migration Announcement

The Notification Team is migrating our email service provider from Postmark to AWS Simple Email Service (SES) ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...