Splunk Search

List fields after rare command

bmer
Explorer

Hi,

Iam using below splunk to help identify least common values of runTime field in myEventRecType file . i get the results .

However I would like to also show additional fields related to the runTime like requestIdqueryExecutionTime,TimeOfExecution. How can I get them added?

Index=abc source=xxx earliest=-60m EventRecType=xyz
| rare runTime limit=5

 

Thanks!

 

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

You can't "add" fields to the results. It wouldn't make sense anyway since "rare" is a transforming command and does aggregation on the original data so other fields' values do not correspond 1:1 to the aggregations.

What you might try doing instead is using stats (or eventstats but that's more limited).

For example:

index=abc source=xxx earliest=-60m EventRecType=xyz
| stats count values(otherField) as otherField values(anotherField) as anotherField by runTime
| sort runTime
| head 5

EDIT: I'm not editing the search because @ITWhisperer 's remark will stop making sense but indeed - the sort is on runTime whereas it should be on count.

ITWhisperer
SplunkTrust
SplunkTrust

I think you probably would want to sort by count not runTime and you can do the head in the sort

index=abc source=xxx earliest=-60m EventRecType=xyz
| stats count values(otherField) as otherField values(anotherField) as anotherField by runTime
| sort 5 count

PickleRick
SplunkTrust
SplunkTrust

You're 100% right. Since we want the rarest ones, we need to sort on count. It was late when I wrote this 😉

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Perhaps the simplest way to do this is with a subsearch, however, there are limits to the number of events so this may not work for your usecase

Index=abc source=xxx earliest=-60m EventRecType=xyz [search Index=abc source=xxx earliest=-60m EventRecType=xyz
| rare runTime limit=5
| fields runTime
| format]
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...