Is there a SPL query pattern that can perform "hierarchical counting" beyond the two levels of depth outlined in these linked answers?
https://community.splunk.com/t5/Splunk-Search/Group-by-two-or-many-fields-fields/m-p/331415
For example, assume a dataset of car make, model, and transmission type. Show the count by make, then count by make and model, then count by make and model and transmission type. That's 3 levels of depth.
| stats count by make model transmission
| eventstats sum(count) as count_m_m by make model
| eventstats sum(count) as count_m by make
| stats count by make model transmission
| eventstats sum(count) as count_m_m by make model
| eventstats sum(count) as count_m by make
That worked nicely, thank you! I wish that I had an easier time thinking this way in SPL.
I added a table with the make, make count, model, model count, transmission and transmission count, and that did the trick. Now I'm going to move onto list value deduping to reduce clutter and see if I can get the different levels of hiearchical counting to line up visually. I'm not holding a lot of confidence in my prospects that way, but you solved the fundamental counting query flow. Thanks again.