Splunk Search

How to make a search sentence

honobe
Explorer

For each subject in the search sentence, the count number is displayed.
In addition to the information currently being displayed, I want to display the attached file name for each subject.

The search sentence you are using is below.
※ Partially omitted

index=xxxxx
| lookup ~ommitted~
| stats count ~ommitted~ by subject

Can I display the attached file name by adding it to the search sentence that is counting?

-image table-

Subject---Number---attached file name---Number of Mail with Attachment

AAAA---100--- aaaa---10
BBBB---50---none---0
CCCC---200---cccc---200

In the current search searches, only the subject line and number of items are displayed.
*I want to display none if there is no attached file.

Tags (1)
0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust
index=xxxxx
| lookup ~ommitted~
| stats count values("attached file name") ~ommitted~ by subject

Or list("attached file name") would work too. List gets you ALL of the values in order, values gets something more like a distinct list of file names. You can try both and see which fits your needs better.

Happy Splunking,
Rich

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust
index=xxxxx
| lookup ~ommitted~
| stats count values("attached file name") ~ommitted~ by subject

Or list("attached file name") would work too. List gets you ALL of the values in order, values gets something more like a distinct list of file names. You can try both and see which fits your needs better.

Happy Splunking,
Rich

0 Karma

honobe
Explorer

Thanks to your answer, I was able to solve the problem.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...