Splunk Search

How to create a search that will show other fields like dest_bunit with the port?

jregexsaurus
Engager

This search will display port numbers from the Endpoint datamodel

| tstats 'summariesonly ' count from datamodel=EndPoint.Port.dest_port 

I would like to create a search that will show other fields like dest_bunit with the port.

Without the datamodel I could just do a stats count by dest port.  I'm not sure how to replicate this query using the datamodel. 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The syntax may not be exactly right, but have you tried something like this?

| tstats `summariesonly` count, values(Endpoint.Port.dest_bunit) as dest_bunits from datamodel=EndPoint.Port.dest_port 
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The syntax may not be exactly right, but have you tried something like this?

| tstats `summariesonly` count, values(Endpoint.Port.dest_bunit) as dest_bunits from datamodel=EndPoint.Port.dest_port 
---
If this reply helps you, Karma would be appreciated.

VatsalJagani
SplunkTrust
SplunkTrust

Or this:

| tstats `summariesonly` count as dest_bunits from datamodel=EndPoint.Port by Endpoint.Port.dest_port, Endpoint.Port.dest_bunit

If not, try below:

| tstats `summariesonly` count as dest_bunits from datamodel=EndPoint.Port by Port.dest_port, Port.dest_bunit

  

I hope this helps!!!

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...