Splunk Search

Why am I unable to return the correct count of all events with FieldA that contain ValueA?

kabiraj
Path Finder

Hi All,

I am facing some problem with my below search:

sourcetype="clientevents" event_error_code=RB_VOD_BUFFER_UNDERFLOW eventItemID="*" | stats count(eval(eventItemID="*BT*")) as "BT_VOD_buffer_underrun_count" count(eval(eventItemID!="")) as "Total_VOD_buffer_underrun_count" 

Here the "BT_VOD_buffer_underrun_count" is always returning zero. The problem lies with count(eval(eventItemID="*BT*")). I have also tried searchmatch, but every time it returns an error.

I want to count all events with "eventItemID" field containing "BT" in its value.

Please help.
Please help.

Tags (3)
0 Karma
1 Solution

laserval
Communicator

You should be able to use like() in the eval expression to match with wildcards:

sourcetype="clientevents" event_error_code=RB_VOD_BUFFER_UNDERFLOW eventItemID="*" | stats count(eval(like(eventItemID,"%BT%"))) as "BT_VOD_buffer_underrun_count" count(eval(!like(eventItemID, "%BT%"))) as "Total_VOD_buffer_underrun_count" 

But it would be less verbose to eval a field first, and do the stats on that, something like:

sourcetype="clientevents" event_error_code=RB_VOD_BUFFER_UNDERFLOW eventItemID="*" | eval eventItemIdType=if(like(eventItemID,"%BT%"), "BT_VOD_buffer_underrun_count", "Total_VOD_buffer_underrun_count") | stats count by eventItemIdType

View solution in original post

laserval
Communicator

You should be able to use like() in the eval expression to match with wildcards:

sourcetype="clientevents" event_error_code=RB_VOD_BUFFER_UNDERFLOW eventItemID="*" | stats count(eval(like(eventItemID,"%BT%"))) as "BT_VOD_buffer_underrun_count" count(eval(!like(eventItemID, "%BT%"))) as "Total_VOD_buffer_underrun_count" 

But it would be less verbose to eval a field first, and do the stats on that, something like:

sourcetype="clientevents" event_error_code=RB_VOD_BUFFER_UNDERFLOW eventItemID="*" | eval eventItemIdType=if(like(eventItemID,"%BT%"), "BT_VOD_buffer_underrun_count", "Total_VOD_buffer_underrun_count") | stats count by eventItemIdType

laserval
Communicator

Note that the second search gives a different result, so you probably want to modify it.

0 Karma

kabiraj
Path Finder

Thanks laserval!

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...