Splunk Search

Splitting results by matched conditions

mahesh27
Communicator

|tstats count where index=app-data  (TERM(Errors) TERM( Started) TERM( in)  TERM(*s)  TERM(*ms))  OR (TERM(system)  TERM(restart))

when i run the above query i am getting overall(combined) results. but i want to see the results for each and every string  separately which i mentioned in the query.

how can i do that????

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

You can't do that. Splunk doesn't keep track of which part of the condition was matched on a particular result line. And you can only split your aggregation on a field or prefixed value.

0 Karma

mahesh27
Communicator

Ok if that is a case we can do without tstats using eval command

May I know how can I do that

 

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

I don't quite follow, to be honest.

Of course you could go through a list of terms to match  over event by event and set a field in case it matched but it will be way way way worse performance-wise.

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...