Splunk Search

New line with count eval match

levent_kurt
Explorer

Hi,

I did a search of search engine bots and divide them by number and take their total calls.
This one is for google. Now I try to add also a new line on the result and print also yandex, yahoo, bing but i can not make them write on the new line with the same result. How can i do it?

sourcetype="access_*" |stats count(eval(match(useragent, "Googlebot/2.1"))) as "Googlebot/2.1",count(eval(match(useragent, "Googlebot-News"))) as "Googlebot-News",count(eval(match(useragent, "Googlebot-Image/1.0"))) as "Googlebot-Image/1.0" ,count(eval(match(useragent, "Googlebot-Video/1.0"))) as "Googlebot-Video/1.0",count(eval(match(useragent, "Googlebot-Mobile/2.1"))) as "Googlebot-Mobile/2.1",count(eval(match(useragent, "Google Web Preview"))) as "Google Web Preview", count(eval(match(useragent, "Feedfetcher-Google"))) as "Feedfetcher-Google"| eval "Google_TOTAL"='Googlebot/2.1'+'Googlebot-News'+'Googlebot-Image/1.0'+'Googlebot-Video/1.0'+'Googlebot-Mobile/2.1'+'Google Web Preview'+'Feedfetcher-Google'
0 Karma
1 Solution

somesoni2
Revered Legend

You can concatenate the output lines for different search engines (e.g. Google_TOTAL, Yahoo_TOTAL etc), using a delimiter and split the final string using that delimiter. The splitted string will be a multivalued field and all TOTAL will appear in new line.

e.g.

your search generating TOTAL fields like Google_TOTAL,Yahoo_TOTAL,Bing_TOTAL | eval TOTAL=split(Google_TOTAL."##".Yahoo_TOTAL."##".Bing_TOTAL, "##")

View solution in original post

0 Karma

somesoni2
Revered Legend

You can concatenate the output lines for different search engines (e.g. Google_TOTAL, Yahoo_TOTAL etc), using a delimiter and split the final string using that delimiter. The splitted string will be a multivalued field and all TOTAL will appear in new line.

e.g.

your search generating TOTAL fields like Google_TOTAL,Yahoo_TOTAL,Bing_TOTAL | eval TOTAL=split(Google_TOTAL."##".Yahoo_TOTAL."##".Bing_TOTAL, "##")
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...