Splunk Search

How to group two field and count content?

b1211ry
Explorer

Hi, I have table below

table.jpg

then I need to grouping field and need to eval (+ )the value become below table

Goal.jpg

Help please..🙏

Labels (1)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@b1211ry - You can try adding the below lines at the bottom of your search:

| appendpipe [| rename Application as Common_ProcessName, count_application as count_process]
| stats sum(count_process) as count_process by Common_ProcessName

 

Here my test example query:

| makeresults 
| eval Common_ProcessName="Excel", count_process=1, Application="Outlook", count_application=2
| append [| makeresults | eval Common_ProcessName="Outlook", count_process=1]
| fields - _time
| appendpipe [| rename Application as Common_ProcessName, count_application as count_process]
| stats sum(count_process) as count_process by Common_ProcessName

VatsalJagani_0-1671203844985.png

 

Consider accepting/upvoting answer if this helps!!!

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@b1211ry - You can try adding the below lines at the bottom of your search:

| appendpipe [| rename Application as Common_ProcessName, count_application as count_process]
| stats sum(count_process) as count_process by Common_ProcessName

 

Here my test example query:

| makeresults 
| eval Common_ProcessName="Excel", count_process=1, Application="Outlook", count_application=2
| append [| makeresults | eval Common_ProcessName="Outlook", count_process=1]
| fields - _time
| appendpipe [| rename Application as Common_ProcessName, count_application as count_process]
| stats sum(count_process) as count_process by Common_ProcessName

VatsalJagani_0-1671203844985.png

 

Consider accepting/upvoting answer if this helps!!!

0 Karma

b1211ry
Explorer

Many Thanks @VatsalJagani!! Problem solved..

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It might be easier to go back a step - how did you create the table in the first place?

0 Karma
Get Updates on the Splunk Community!

Unleash the Power of Splunk MCP and AI, Meet Us at .Conf 2025, and Find Even More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Professionals: Build Resilience and Visibility with These .conf25 ...

  If you're focused on performance, availability, and full-stack visibility, the Observability track at ...

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...