Splunk Search

How to increment counter field with a by clause

e_sherlock
Explorer

Given events

Group MultiValue

A 7,2,9

B 8,1

I'm using makemv to pivot the results to below, but I also want a new Index/Counter field which counts (or shows the index value) and resets when it sees a new group. The accum command doesn't support a "by [field list]" so curious how to do this?

Group Value **Index/Counter**


A 7 1

A 2 2

A 9 3

B 8 1

B 1 2

Tags (3)
1 Solution

e_sherlock
Explorer

Got it working like this:

| streamstats count as index by Group

View solution in original post

e_sherlock
Explorer

Got it working like this:

| streamstats count as index by Group

sloshburch
Ultra Champion

Or just | stats count as index by Group should work I assume.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...