Splunk Search

How to make a search sentence

honobe
Explorer

For each subject in the search sentence, the count number is displayed.
In addition to the information currently being displayed, I want to display the attached file name for each subject.

The search sentence you are using is below.
※ Partially omitted

index=xxxxx
| lookup ~ommitted~
| stats count ~ommitted~ by subject

Can I display the attached file name by adding it to the search sentence that is counting?

-image table-

Subject---Number---attached file name---Number of Mail with Attachment

AAAA---100--- aaaa---10
BBBB---50---none---0
CCCC---200---cccc---200

In the current search searches, only the subject line and number of items are displayed.
*I want to display none if there is no attached file.

Tags (1)
0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust
index=xxxxx
| lookup ~ommitted~
| stats count values("attached file name") ~ommitted~ by subject

Or list("attached file name") would work too. List gets you ALL of the values in order, values gets something more like a distinct list of file names. You can try both and see which fits your needs better.

Happy Splunking,
Rich

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust
index=xxxxx
| lookup ~ommitted~
| stats count values("attached file name") ~ommitted~ by subject

Or list("attached file name") would work too. List gets you ALL of the values in order, values gets something more like a distinct list of file names. You can try both and see which fits your needs better.

Happy Splunking,
Rich

0 Karma

honobe
Explorer

Thanks to your answer, I was able to solve the problem.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...