Splunk Search

Passing a count to a token used for a label in Single

jdbtee
Path Finder

Hi

I have a single which shows the total assets after a search.

I then want to add a token so that i can use the result of that search to add it a label, to show value /$value$

so: index="123" | search field="abc " AS foo | count(foo) AS $tkn_bar$ | [search index="456" | search field2="def" AS new | count(new) AS new | fields new

So the single would show: new

Then in the label it would be: / $tot_bar$ which would really be "/ foo.count"

So the final single would display: new / foo.count

0 Karma
1 Solution

somesoni2
Revered Legend

Try this

 index="456" | search field2="def" AS new | count(new) AS new | appendcols [search index="123" | search field="abc " AS foo | count(foo) as temp]  | eval final=new."/".temp | fields final

View solution in original post

somesoni2
Revered Legend

Try this

 index="456" | search field2="def" AS new | count(new) AS new | appendcols [search index="123" | search field="abc " AS foo | count(foo) as temp]  | eval final=new."/".temp | fields final

jdbtee
Path Finder

Perfect cheers

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...