Splunk Search

How to get values count to display in table?

NizanCohen
Explorer

Hi all.

I wish to display in a table format the value's count.

For example;

Computer A has 100 sessions.

Computer B has 50 sessions.

I want to display the 100 and and the 50 values alongside "Computer A" and "Computer B".

 

Thanks!

Labels (1)
0 Karma
1 Solution

FrankVl
Ultra Champion

Sounds like all you need is to add the following to your query:

| stats count by fieldname

Where "fieldname" should be whatever field you want to see the counts of.

Alternatively, if you only want the top ten for example, you can also take a look at the top command

View solution in original post

0 Karma

NizanCohen
Explorer

No, those are general example that express my search.

Let me explain more: 

1. I have the fields inside "Interesting fields"

2. I select one - for example: "Username" - and click on it.

3.  I get top 10 values with the used usernames and their count.

4. I wish to display in a table (or any other way) the count of the used usernames.

 

Hope this explains it better.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats count by username
0 Karma

FrankVl
Ultra Champion

Sounds like all you need is to add the following to your query:

| stats count by fieldname

Where "fieldname" should be whatever field you want to see the counts of.

Alternatively, if you only want the top ten for example, you can also take a look at the top command

0 Karma

NizanCohen
Explorer

YES.

Thank you!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Are those examples of your events?

Do you have any fields already extracted?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...