I am getting fewer events when using rename command in splunk. ( Compared to the search where I haven't used rename). What could be the reason behind this?
Without rename:
index="A" sourcetype="B"
| stats values(project_name2), count(linecount) by pod
| sort - count(linecount) | head 10
With rename:
index="A" sourcetype="B"
| stats values(project_name2) as project count(linecount) as lines by pod
| sort - count(linecount) | head 10
Hi @vjsplunk,
the reason is that in the second case you don't have more ths field "count(linecount)" but the field "lines", so when you sort you have few events, please try this:
index="A" sourcetype="B"
| stats values(project_name2) AS project count(linecount) AS lines BY pod
| sort -lines
| head 10
Ciao.
Giuseppe