Splunk Search

date_month issue

iamniks
Explorer

"source="jun_jan.csv" | stats count by date_month" lists all months, but if I want to include another field like status ""source="jun_jan.csv" | stats count by date_month, STATUS" It lists only two months. Plese suggest how do we get the other field

source="jun_jan.csv" | stats count by date_mont
date_month count

1 august 2776
2 december 4602
3 january 5228
4 july 3533
5 november 5001
6 october 3357
7 september 4275

source="jun_jan.csv" | stats count by date_month, STATUS
date_month STATUS count

1 august FAILED 262
2 august PASSED 2046
3 august WARNING_FAILED_STEP 23
4 august WARNING_FILTER 14
5 july FAILED 433
6 july NONE 1
7 july PASSED 3002
8 july WARNING_FAILED_STEP 76
9 july WARNING_FILTER 21

Tags (3)
0 Karma

ziegfried
Influencer

Look at the events that are in months, not displayed in the second result and see if the STATUS field is present there. The search ... | stats count by date_month,STATUS will only show the result counts for events with both fields present.

0 Karma

ziegfried
Influencer

is there a date_month field too for all of them?

0 Karma

iamniks
Explorer

For all the events there is a status as well as process field,

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...