- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Palo Alto Networks vendor_action query to list all
splunkymcsnypr
Engager
03-10-2021
03:24 AM
I'd like to run an efficient search over an index to find all of the types of 'vendor_action' field present in the data. However, this is a very large dataset so is there a low resource search to do this?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
scelikok

SplunkTrust
03-13-2021
01:58 AM
Hi @splunkymcsnypr,
You can use stats;
| stats count by vendor_action
If this reply helps you an upvote and "Accept as Solution" is appreciated.
