Splunk Search

How to get the populer distribution channel by geographicaly

gajananh999
Contributor

Dear All,

I have a data of insurance i want to check which is most popular channel of distribution by state.

Thanks and regards
Gajanan Hiroji

Tags (1)
0 Karma
1 Solution

Ayn
Legend

Well...

<yourbasesearch> | stats count by Channel,US_State

?

View solution in original post

0 Karma

Ayn
Legend

Well...

<yourbasesearch> | stats count by Channel,US_State

?

0 Karma

gajananh999
Contributor

Hey Ayn Thank you so much i got it what i want.

0 Karma

Ayn
Legend

There we go, it's easier to know what you mean when you give direct examples...

... | top 1 Channel by US_State

should give you what you want.

0 Karma

gajananh999
Contributor

This will give you all the channel with all the states i want all state with popular channel

it should be like

albama Direct
alaska Online
texas Broker

0 Karma

gajananh999
Contributor

Hey Ayn,
I Have Channel like
1. Direct
2. Agent
3. Broker
4. online

Every Policy created by using any one of this Channel.

So i have residency address of Policy Holder so i want find which Channel is popular in which all states

I extracted the US_State from the address of the Policy Holder

I think this will give you all you wanted.

0 Karma

Ayn
Legend

We need way more details than this. What does your data look like? What did you do so far (create field extractions, setup sourcetypes, ...?) What "channels of distributions" are you talking about? What exactly would be your desired end result?

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...