Splunk Search
Highlighted

Stats showing count of 1 result vs NOT that result

Path Finder

I am super new to using the powerful eval command but cannot quite get my head around the syntax. Can someone help me?

I am trying to show stats to show how many useragents have the word bot somewhere in the field vs those that do not.

... | eval type=BOT if(useragent="*bot*")|eval type=NOT if(useragent!="*bot*")|stats count by type
Tags (4)
0 Karma
Highlighted

Re: Stats showing count of 1 result vs NOT that result

SplunkTrust
SplunkTrust

Try like this

your base search | eval type=if(like(useragent,"%bot%"),"BOT","NOT") | stats count by type
Highlighted

Re: Stats showing count of 1 result vs NOT that result

Splunk Employee
Splunk Employee

Try:

    ... | eval type=if(match(useragent, ".*bot.*"), "BOT", "NOT")|stats count by type

View solution in original post

Highlighted

Re: Stats showing count of 1 result vs NOT that result

Path Finder

Thanks both d and somesoni2, you were both correct. Thanks!
(I cannot add comments to your answers)

Highlighted

Re: Stats showing count of 1 result vs NOT that result

Community Manager
Community Manager

Hi @KindaWorking

Glad you got two awesome answers! Question though for you. What happened exactly when you tried to comment on their answers? Did you receive an error or did a message pop up saying something about not having enough karma or permissions? This might be a bug we thought was fixed already.

0 Karma
Highlighted

Re: Stats showing count of 1 result vs NOT that result

Path Finder

Hi ppablo, it said that I did not have enough karma.

0 Karma
Highlighted

Re: Stats showing count of 1 result vs NOT that result

Community Manager
Community Manager

Thanks for confirming. It should be fixed now, but if you're still unable to comment on other users' answers/comments, just let me know.

0 Karma