Splunk Search

Unfamiliar Syntax in Query

inovexsean
Explorer

I have a query, written by someone else, that I'm trying to understand: tstats count as count sum(sessionLength) as volume where (index=accm_*) name="John",selectors{}.category{}=* by selectors{}.categories{}, |.... I can not find a reference anywhere for the selectors{}.category{}. Could someone please point me in the right direction? Thanks.

Tags (1)
0 Karma
1 Solution

mayurr98
Super Champion

First of all are you getting output? query fails here itself at index-accm_* it should be index=accm_* can you paste entire query in 101010 sample code format.

View solution in original post

0 Karma

mayurr98
Super Champion

First of all are you getting output? query fails here itself at index-accm_* it should be index=accm_* can you paste entire query in 101010 sample code format.

0 Karma

inovexsean
Explorer

Sorry, that was a typo on my part. Due to sensitivity I cannot copy paste the entire query.

0 Karma

mayurr98
Super Champion

okay now it looks better so if you look the raw data in verbose mode that is type this search query index=accm_* name=* you should see a field name selectors{}.categories{}.

You are basically doing event count and sum of session length by categories(values in the selectors{}.categories{} field )

inovexsean
Explorer

Okay, so that's just some kind of internal field name that you only see when verbose mode is enabled. Thank you.

0 Karma

mayurr98
Super Champion

yeah the query is written in tstats (which will not allow you to look at the raw data and is basically use for faster processing of searches when data model acceleration is ON)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...