Splunk Search

Splunk query to show my entire security metrics which is 68 in number

ngwodo
Path Finder

The splunk query below is only showing just one line of Metric_ID which starts at 1. I need help with the splunk query that we show all the  68 lines of Metric_ID starting from 1. 

 

index=security sourcetype="Computers" "Computer Status"=Enabled
| bin _time span=1day
| dedup _time sAMAccountName
| timechart span=1day count |search count > 0
| stats avg(count) AS avg stdev(count) AS stdev min(count) AS min max(count) AS max latest(count) AS latest_count
| eval min_thres=5000, max_thres=7500
| eval alert=if((latest_count<min_thres OR latest_count>max_thres), 1, 0)
| eval Metric_ID="1"
| lookup  free_metrics.csv Metric_ID output Data_Item_volatility, Metric_ID, Metric_Name

Labels (1)
0 Karma

to4kawa
Ultra Champion

| eval Metric_ID="1"

>The splunk query below is only showing just one line of Metric_ID which starts at 1.

of course.

>all the  68 lines

I don't have any information here.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...