Hello Splunkers,
I have this query which looks for HTTPS connections on web proxy layer made by users when there is specific amount of data sent out to external sites. Right now for every match I get a separate line of log. How could I format my results to get amount of data sent only for the different domains. As an example, if I have right now:
domain1 500bytes
domain1 400bytes
domain1 10000bytes
domain2 480bytes
domain2 4000bytes
Instead i'd like to get:
domain1 10900bytes
domain2 4480bytes
Thanks.
Try this
<your search to get details> | stats sum(<your data amount field> by domain
Try this
<your search to get details> | stats sum(<your data amount field> by domain