Splunk Search

date_month issue

Explorer

"source="jun_jan.csv" | stats count by date_month" lists all months, but if I want to include another field like status ""source="jun_jan.csv" | stats count by date_month, STATUS" It lists only two months. Plese suggest how do we get the other field

source="jun_jan.csv" | stats count by date_mont
date_month count

1 august 2776
2 december 4602
3 january 5228
4 july 3533
5 november 5001
6 october 3357
7 september 4275

source="jun_jan.csv" | stats count by date_month, STATUS
date_month STATUS count

1 august FAILED 262
2 august PASSED 2046
3 august WARNING_FAILED_STEP 23
4 august WARNING_FILTER 14
5 july FAILED 433
6 july NONE 1
7 july PASSED 3002
8 july WARNING_FAILED_STEP 76
9 july WARNING_FILTER 21

Tags (3)
0 Karma

Influencer

Look at the events that are in months, not displayed in the second result and see if the STATUS field is present there. The search ... | stats count by date_month,STATUS will only show the result counts for events with both fields present.

0 Karma

Influencer

is there a date_month field too for all of them?

0 Karma

Explorer

For all the events there is a status as well as process field,

0 Karma