Can we aggregate the data in the specified column?
example SPL A)
index=pan_logs | stats count by signature,src,dest
example SPL A Result)
signature_name | src | dest | count |
signature-A | 10.1.1.1 | 10.0.0.1 | 1 |
signature-B | 10.1.1.2 | 10.0.0.2 | 2 |
signature-A | 10.1.1.3 | 10.0.0.3 | 2 |
signature-B | 10.1.1.4 | 10.0.0.4 | 2 |
Want to creat table)
signature_name | src | dest | count |
signature-A | 10.1.1.1 | 10.0.0.1 | 3 |
10.1.1.3 | 10.0.0.3 | ||
signature-B | 10.1.1.2 | 10.0.0.2 | 4 |
10.1.1.4 | 10.0.0.4 |
We want to aggregate by signature_name without changing src<->dest combination.
Hi @ko1,
it's not possible to display results in the format you want, Splunk isn't Excel!
but you can do something like this:
index=pan_logs
| eval col="src=".src." dest=".dest
| stats values(col) AS "src dest" count BY signature
Ciao.
Giuseppe
| stats list(src) as src list(dest) as dest sum(count) as count by signature_name
Hi @ko1,
it's not possible to display results in the format you want, Splunk isn't Excel!
but you can do something like this:
index=pan_logs
| eval col="src=".src." dest=".dest
| stats values(col) AS "src dest" count BY signature
Ciao.
Giuseppe
Hi, @gcusello .
I will use this.
Thanks a lot!
Hi @ko1 ,
if one answer solves your need, please accept this one for the other people of Community or tell us how we can help you.
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated by all the Contributors;-)