Splunk Search

Passing a count to a token used for a label in Single

jdbtee
Path Finder

Hi

I have a single which shows the total assets after a search.

I then want to add a token so that i can use the result of that search to add it a label, to show value /$value$

so: index="123" | search field="abc " AS foo | count(foo) AS $tkn_bar$ | [search index="456" | search field2="def" AS new | count(new) AS new | fields new

So the single would show: new

Then in the label it would be: / $tot_bar$ which would really be "/ foo.count"

So the final single would display: new / foo.count

0 Karma
1 Solution

somesoni2
Revered Legend

Try this

 index="456" | search field2="def" AS new | count(new) AS new | appendcols [search index="123" | search field="abc " AS foo | count(foo) as temp]  | eval final=new."/".temp | fields final

View solution in original post

somesoni2
Revered Legend

Try this

 index="456" | search field2="def" AS new | count(new) AS new | appendcols [search index="123" | search field="abc " AS foo | count(foo) as temp]  | eval final=new."/".temp | fields final

jdbtee
Path Finder

Perfect cheers

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...