Splunk Search

Using Tags to group results

richnavis
Contributor

I know that I can use tags to define a search, but can I also use them to group results? In my situation, I want to search my servers, and have them grouped by the type of servers I have. So...

I have created a tag called "Linux" and Another Tag called "Windows", then have created field value pairs to tag the servers. It it possible to then query them and get a count?

I've tried the following, but doesn't return any results.

Search tag=Linux or tag=Windows | stats count(host) by tag::host

I'm on 4.2.1

Tags (2)
0 Karma

richnavis
Contributor

So.. Found out that this is NOT possible... However, one way to do this is to create a lookup list, and then group by the fields in the lookup list..

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...