Splunk Search

help on basic table

jip31
Motivator

Hello

I use the search below :

[| inputlookup host.csv 
    | table host] index="x" sourcetype="PerfmonMk:Process" process_name=chrome ("%_Processor_Time"=0) 
| lookup lookup_cmdb_fo_all.csv HOSTNAME as host output SITE 
| search SITE=$tok_filtersite|s$ 
| stats  count(process_name) as Total by host
| sort -Total limit=10

I need to display host, SITE and Total fields
I m doing

   | table host SITE Total

But SITE doenst display
What I have to do please?

Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

When you use stats in your query it will drop remaining fields. So try this | stats count(process_name) as Total, values(SITE) as SITE by host

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi,

When you use stats in your query it will drop remaining fields. So try this | stats count(process_name) as Total, values(SITE) as SITE by host

0 Karma

jip31
Motivator

Oh many thanks

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...