Splunk Search

Splunk query to show my entire security metrics which is 68 in number

ngwodo
Path Finder

The splunk query below is only showing just one line of Metric_ID which starts at 1. I need help with the splunk query that we show all the  68 lines of Metric_ID starting from 1. 

 

index=security sourcetype="Computers" "Computer Status"=Enabled
| bin _time span=1day
| dedup _time sAMAccountName
| timechart span=1day count |search count > 0
| stats avg(count) AS avg stdev(count) AS stdev min(count) AS min max(count) AS max latest(count) AS latest_count
| eval min_thres=5000, max_thres=7500
| eval alert=if((latest_count<min_thres OR latest_count>max_thres), 1, 0)
| eval Metric_ID="1"
| lookup  free_metrics.csv Metric_ID output Data_Item_volatility, Metric_ID, Metric_Name

Labels (1)
0 Karma

to4kawa
Ultra Champion

| eval Metric_ID="1"

>The splunk query below is only showing just one line of Metric_ID which starts at 1.

of course.

>all the  68 lines

I don't have any information here.

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...