Splunk Search

Remove Line from stats based on value of line

WindWalker
Engager

So I am writing a query and It all gets piped into stats at the end. There is a value that I want to use to remove lines from stats as the line item is unnecessary. I understand that by will list every item but I'm looking to remove particular lines based upon a certain condition as it will help cleanup my data. What im looking todo is I run a distinct_count on an item and then for every line that the dc result is 0, remove it from my results

Labels (1)
0 Karma
1 Solution

WindWalker
Engager

Just solved,

After calling my stats function

|stats <Whatever you have for stats>
| where <condition>

i just called where and it gave me the results im looking for

View solution in original post

0 Karma

WindWalker
Engager

Just solved,

After calling my stats function

|stats <Whatever you have for stats>
| where <condition>

i just called where and it gave me the results im looking for

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...