Splunk Search

date_month issue

iamniks
Explorer

"source="jun_jan.csv" | stats count by date_month" lists all months, but if I want to include another field like status ""source="jun_jan.csv" | stats count by date_month, STATUS" It lists only two months. Plese suggest how do we get the other field

source="jun_jan.csv" | stats count by date_mont
date_month count

1 august 2776
2 december 4602
3 january 5228
4 july 3533
5 november 5001
6 october 3357
7 september 4275

source="jun_jan.csv" | stats count by date_month, STATUS
date_month STATUS count

1 august FAILED 262
2 august PASSED 2046
3 august WARNING_FAILED_STEP 23
4 august WARNING_FILTER 14
5 july FAILED 433
6 july NONE 1
7 july PASSED 3002
8 july WARNING_FAILED_STEP 76
9 july WARNING_FILTER 21

Tags (3)
0 Karma

ziegfried
Influencer

Look at the events that are in months, not displayed in the second result and see if the STATUS field is present there. The search ... | stats count by date_month,STATUS will only show the result counts for events with both fields present.

0 Karma

ziegfried
Influencer

is there a date_month field too for all of them?

0 Karma

iamniks
Explorer

For all the events there is a status as well as process field,

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...