Splunk Search

Remove Line from stats based on value of line

WindWalker
Engager

So I am writing a query and It all gets piped into stats at the end. There is a value that I want to use to remove lines from stats as the line item is unnecessary. I understand that by will list every item but I'm looking to remove particular lines based upon a certain condition as it will help cleanup my data. What im looking todo is I run a distinct_count on an item and then for every line that the dc result is 0, remove it from my results

Labels (1)
0 Karma
1 Solution

WindWalker
Engager

Just solved,

After calling my stats function

|stats <Whatever you have for stats>
| where <condition>

i just called where and it gave me the results im looking for

View solution in original post

0 Karma

WindWalker
Engager

Just solved,

After calling my stats function

|stats <Whatever you have for stats>
| where <condition>

i just called where and it gave me the results im looking for

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...