Splunk Search

To find the count of specific fields

Real_captain
Path Finder

Hi Team 

I want to know if it is possible to find the count of specific fields and show them in different columns.

Example : 

Real_captain_0-1712743767116.png

 

 

For the above example, i want the result in the below format:

| Date | File RPWARDA | Count of File SPWARAA |  Count of File SPWARAA | Count of File SPWARRA | Diff (RPWARDA   - ( SPWARAA +SPWARRA ) ) |

|2024/04/10 | 49 | 38 | 5 | 6 |

 

Is it possible using a splunk query ? 

 

Original query : 

index=events_prod_cdp_penalty_esa source="SYSLOG"
(TERM(NIDF=RPWARDA) OR TERM(NIDF=SPWARAA) OR TERM(NIDF=SPWARRA))
| rex field=TEXT "NIDF=(?<file>[^\\s]+)"
| eval DIR = if(file="RPWARDA" ,"IN","OUT")
| convert timeformat="%Y/%m/%d" ctime(_time) AS Date
| stats count by Date , file , DIR

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. I don't see why you calculate the IN/OUT parameter if you don't need this value in the end.

2. Assuming you don't need the DIR field, you can simply use xyseries to... put your values into a x/y table.

| xyseries Date file count

 Now you can just calculate your sum/difference of various files as you have them as separate fields. (you might have to fillnull with zero if you have blank spaces).

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @Real_captain,

You can try below;

index=events_prod_cdp_penalty_esa source="SYSLOG" (TERM(NIDF=RPWARDA) OR TERM(NIDF=SPWARAA) OR TERM(NIDF=SPWARRA))
| rex field=TEXT "NIDF=(?<file>[^\\s]+)"
| convert timeformat="%Y/%m/%d" ctime(_time) AS Date
| stats count(eval(file="RPWARDA")) AS RPWARDA, count(eval(file="SPWARAA")) AS SPWARAA, count(eval(file="SPWARRA")) AS SPWARRA by Date
| eval Diff=(RPWARDA-(SPWARAA+SPWARRA))

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...