Splunk Search
Highlighted

How to group and count together the rows based on some field value in splunk?

New Member

Example:
I am having a search in my view code and displaying results in the form of table.
small example result:
custid Eventid
10001 200
10001 300
10002 200
10002 100
10002 300

I got the answer for grouping of the custid's by using the query "stats values(custID) by eventID". I also need to count the custID that has occurred for every Customer. Can anyone suggest me the query for the same? Whatever I use apart from the above query to count the number of custid's I could not get the answers for the same.

Tags (3)
0 Karma
Highlighted

Re: How to group and count together the rows based on some field value in splunk?

Esteemed Legend

Like this:

| stats values(custID) count(custID) dc(custID) BY eventID

View solution in original post

0 Karma