Splunk Search

How to group two field and count content?

b1211ry
Explorer

Hi, I have table below

table.jpg

then I need to grouping field and need to eval (+ )the value become below table

Goal.jpg

Help please..🙏

Labels (1)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@b1211ry - You can try adding the below lines at the bottom of your search:

| appendpipe [| rename Application as Common_ProcessName, count_application as count_process]
| stats sum(count_process) as count_process by Common_ProcessName

 

Here my test example query:

| makeresults 
| eval Common_ProcessName="Excel", count_process=1, Application="Outlook", count_application=2
| append [| makeresults | eval Common_ProcessName="Outlook", count_process=1]
| fields - _time
| appendpipe [| rename Application as Common_ProcessName, count_application as count_process]
| stats sum(count_process) as count_process by Common_ProcessName

VatsalJagani_0-1671203844985.png

 

Consider accepting/upvoting answer if this helps!!!

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@b1211ry - You can try adding the below lines at the bottom of your search:

| appendpipe [| rename Application as Common_ProcessName, count_application as count_process]
| stats sum(count_process) as count_process by Common_ProcessName

 

Here my test example query:

| makeresults 
| eval Common_ProcessName="Excel", count_process=1, Application="Outlook", count_application=2
| append [| makeresults | eval Common_ProcessName="Outlook", count_process=1]
| fields - _time
| appendpipe [| rename Application as Common_ProcessName, count_application as count_process]
| stats sum(count_process) as count_process by Common_ProcessName

VatsalJagani_0-1671203844985.png

 

Consider accepting/upvoting answer if this helps!!!

0 Karma

b1211ry
Explorer

Many Thanks @VatsalJagani!! Problem solved..

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It might be easier to go back a step - how did you create the table in the first place?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...