Splunk Search

How to group the data by date and type, so each entry would count as 1, from SQL Datasource?

Bbyers3
New Member

I have a date in my SQL database that I want to group the data by that date and Type. The Year/Month/Week/Day each entry would count as 1.

Example Dates

1/2/2018 - P
1/5/2018 - P
1/10/2018 - P
1/15/2018 - V
1/20/2018 - V
1/28/2018 - V

Should Produce

Jan - 6
Week 1 - 2P
Week 2 - 1V 1P
Week 3 - 1V
Week 4 - 1V
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...