Splunk Search

How to group two field and count content?

b1211ry
Explorer

Hi, I have table below

table.jpg

then I need to grouping field and need to eval (+ )the value become below table

Goal.jpg

Help please..🙏

Labels (1)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@b1211ry - You can try adding the below lines at the bottom of your search:

| appendpipe [| rename Application as Common_ProcessName, count_application as count_process]
| stats sum(count_process) as count_process by Common_ProcessName

 

Here my test example query:

| makeresults 
| eval Common_ProcessName="Excel", count_process=1, Application="Outlook", count_application=2
| append [| makeresults | eval Common_ProcessName="Outlook", count_process=1]
| fields - _time
| appendpipe [| rename Application as Common_ProcessName, count_application as count_process]
| stats sum(count_process) as count_process by Common_ProcessName

VatsalJagani_0-1671203844985.png

 

Consider accepting/upvoting answer if this helps!!!

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@b1211ry - You can try adding the below lines at the bottom of your search:

| appendpipe [| rename Application as Common_ProcessName, count_application as count_process]
| stats sum(count_process) as count_process by Common_ProcessName

 

Here my test example query:

| makeresults 
| eval Common_ProcessName="Excel", count_process=1, Application="Outlook", count_application=2
| append [| makeresults | eval Common_ProcessName="Outlook", count_process=1]
| fields - _time
| appendpipe [| rename Application as Common_ProcessName, count_application as count_process]
| stats sum(count_process) as count_process by Common_ProcessName

VatsalJagani_0-1671203844985.png

 

Consider accepting/upvoting answer if this helps!!!

0 Karma

b1211ry
Explorer

Many Thanks @VatsalJagani!! Problem solved..

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It might be easier to go back a step - how did you create the table in the first place?

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...