Splunk Search

How to search and table count for multiple fields?

vtsguerrero
Contributor

Can anyone help me making this table?
I have the field Status, wich has events Status=1, Status=2, Status=3.
I need to count events for each and make a table for each, example

Channel | Total Status = 1 | Total Status = 2 | Total Status = 3

Channel A
Channel B
Channel C

This is my current query:

index=main sourcetype=control | stats count, values(Status) as Status by STATUS | table Channel, count

Tags (3)
1 Solution

Ayn
Legend
index=main sourcetype=control | chart count over Channel by STATUS

?

View solution in original post

Ayn
Legend
index=main sourcetype=control | chart count over Channel by STATUS

?

vtsguerrero
Contributor

Thanks a lot Ayn! Solved my problems! 😄

0 Karma

vtsguerrero
Contributor

I forgot to mention that this table should also show per Channel for each line :X
What's the easiest way I can do this?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...