Splunk Search

How to create a search that will show other fields like dest_bunit with the port?

jregexsaurus
Engager

This search will display port numbers from the Endpoint datamodel

| tstats 'summariesonly ' count from datamodel=EndPoint.Port.dest_port 

I would like to create a search that will show other fields like dest_bunit with the port.

Without the datamodel I could just do a stats count by dest port.  I'm not sure how to replicate this query using the datamodel. 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The syntax may not be exactly right, but have you tried something like this?

| tstats `summariesonly` count, values(Endpoint.Port.dest_bunit) as dest_bunits from datamodel=EndPoint.Port.dest_port 
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The syntax may not be exactly right, but have you tried something like this?

| tstats `summariesonly` count, values(Endpoint.Port.dest_bunit) as dest_bunits from datamodel=EndPoint.Port.dest_port 
---
If this reply helps you, Karma would be appreciated.

VatsalJagani
SplunkTrust
SplunkTrust

Or this:

| tstats `summariesonly` count as dest_bunits from datamodel=EndPoint.Port by Endpoint.Port.dest_port, Endpoint.Port.dest_bunit

If not, try below:

| tstats `summariesonly` count as dest_bunits from datamodel=EndPoint.Port by Port.dest_port, Port.dest_bunit

  

I hope this helps!!!

Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...