Splunk Search

How to group by multiple fields?

rsahoo
Engager

I have a data set from where I am trying to apply the group by function on multiple columns. I tried stats with list and ended up with this output.

country state time #travel
India Bangalore
20220326023652
1
   
20220326023652
1
   
20220327023321
1
   
20220327023321
1
   
20220327023321
1

Whereas I am looking for something below ...

country state time #travel
India Bangalore
20220326023652
2
   
20220327023321
3

 

Any suggestions on the right query please!

Labels (1)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Without a verbal description of the actual requirement, this is my speculation of the intention: country and state are uniquely determined by time, and #travel is added up.

| stats values(country) as country values(state) as state sum("#travel") as "#travel" by time
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...