Splunk Search

Palo Alto Networks vendor_action query to list all

splunkymcsnypr
Engager

I'd like to run an efficient search over an index to find all of the types of 'vendor_action' field present in the data. However, this is a very large dataset so is there a low resource search to do this? 

Labels (4)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @splunkymcsnypr,

You can use stats;

| stats count by vendor_action
If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...