Splunk Search

Need output value

VijaySrrie
Builder

Hi, 

Output of the below query has been attached, I need only the total value to be displayed in the dashboard. 

Here the total value is 578 only that should be displayed in the dashboard

 

index=abc sourcetype=xyz

| rex field=_raw "INFO\s+(?<action>\w+\s\:?\s?\w+\s?\w+\s?\w+\s?\w+\s?\w+)"
| search action="getActiveRecords response" OR action="SUCCESS : get active records"
| stats count by action
| addtotals count col=t row=t labelfield=action label=output

vijaysri_0-1614920799469.png

 

Labels (3)
0 Karma
1 Solution

dave_null
Path Finder

You should be able to add another two lines to filter out the other stuff:

| search action=output
| table Total

View solution in original post

0 Karma

dave_null
Path Finder

You should be able to add another two lines to filter out the other stuff:

| search action=output
| table Total

0 Karma
Get Updates on the Splunk Community!

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...