Splunk Search

How to create a search that will show other fields like dest_bunit with the port?

jregexsaurus
Engager

This search will display port numbers from the Endpoint datamodel

| tstats 'summariesonly ' count from datamodel=EndPoint.Port.dest_port 

I would like to create a search that will show other fields like dest_bunit with the port.

Without the datamodel I could just do a stats count by dest port.  I'm not sure how to replicate this query using the datamodel. 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The syntax may not be exactly right, but have you tried something like this?

| tstats `summariesonly` count, values(Endpoint.Port.dest_bunit) as dest_bunits from datamodel=EndPoint.Port.dest_port 
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The syntax may not be exactly right, but have you tried something like this?

| tstats `summariesonly` count, values(Endpoint.Port.dest_bunit) as dest_bunits from datamodel=EndPoint.Port.dest_port 
---
If this reply helps you, Karma would be appreciated.

VatsalJagani
SplunkTrust
SplunkTrust

Or this:

| tstats `summariesonly` count as dest_bunits from datamodel=EndPoint.Port by Endpoint.Port.dest_port, Endpoint.Port.dest_bunit

If not, try below:

| tstats `summariesonly` count as dest_bunits from datamodel=EndPoint.Port by Port.dest_port, Port.dest_bunit

  

I hope this helps!!!

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...