Splunk Search

Why is stats count by fieldname not working?

pchava
New Member

In search getting list of events and stats giving count of events but when extend the search by field name, throwing "No results yet found" error.

Am I doing anything wrong?

0 Karma
1 Solution

PowerPacked
Builder

Hi @pchava

Check if the field is extracted or not, & are you able to see the field in the list of fields ( Selected Fields & Interesting Fields) on the left handed side

Thanks

View solution in original post

0 Karma

PowerPacked
Builder

Hi @pchava

Check if the field is extracted or not, & are you able to see the field in the list of fields ( Selected Fields & Interesting Fields) on the left handed side

Thanks

0 Karma

pchava
New Member

Hi @PowerPacked,
Its extracted, I can see in Interesting fields (even i tried by moving field from interesting to selected fields).

Thanks.

0 Karma

pchava
New Member

Hi @powerpacked, its working thanks, my bad I missed case sensitive for the field names.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...