Splunk Search

Why am I unable to return the correct count of all events with FieldA that contain ValueA?

kabiraj
Path Finder

Hi All,

I am facing some problem with my below search:

sourcetype="clientevents" event_error_code=RB_VOD_BUFFER_UNDERFLOW eventItemID="*" | stats count(eval(eventItemID="*BT*")) as "BT_VOD_buffer_underrun_count" count(eval(eventItemID!="")) as "Total_VOD_buffer_underrun_count" 

Here the "BT_VOD_buffer_underrun_count" is always returning zero. The problem lies with count(eval(eventItemID="*BT*")). I have also tried searchmatch, but every time it returns an error.

I want to count all events with "eventItemID" field containing "BT" in its value.

Please help.
Please help.

Tags (3)
0 Karma
1 Solution

laserval
Communicator

You should be able to use like() in the eval expression to match with wildcards:

sourcetype="clientevents" event_error_code=RB_VOD_BUFFER_UNDERFLOW eventItemID="*" | stats count(eval(like(eventItemID,"%BT%"))) as "BT_VOD_buffer_underrun_count" count(eval(!like(eventItemID, "%BT%"))) as "Total_VOD_buffer_underrun_count" 

But it would be less verbose to eval a field first, and do the stats on that, something like:

sourcetype="clientevents" event_error_code=RB_VOD_BUFFER_UNDERFLOW eventItemID="*" | eval eventItemIdType=if(like(eventItemID,"%BT%"), "BT_VOD_buffer_underrun_count", "Total_VOD_buffer_underrun_count") | stats count by eventItemIdType

View solution in original post

laserval
Communicator

You should be able to use like() in the eval expression to match with wildcards:

sourcetype="clientevents" event_error_code=RB_VOD_BUFFER_UNDERFLOW eventItemID="*" | stats count(eval(like(eventItemID,"%BT%"))) as "BT_VOD_buffer_underrun_count" count(eval(!like(eventItemID, "%BT%"))) as "Total_VOD_buffer_underrun_count" 

But it would be less verbose to eval a field first, and do the stats on that, something like:

sourcetype="clientevents" event_error_code=RB_VOD_BUFFER_UNDERFLOW eventItemID="*" | eval eventItemIdType=if(like(eventItemID,"%BT%"), "BT_VOD_buffer_underrun_count", "Total_VOD_buffer_underrun_count") | stats count by eventItemIdType

laserval
Communicator

Note that the second search gives a different result, so you probably want to modify it.

0 Karma

kabiraj
Path Finder

Thanks laserval!

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...