Splunk Search
Highlighted

how to use where parameter?

Communicator

Hi,

I am using where clause but it is not giving any result. It showing the result as (0) in counts section. My query is -

eventtype="email_fetching" Fetching | where count>80 | stats count

Kindly suggest where I am wrong?

Thanks
Ankit

Tags (2)
0 Karma
Highlighted

Re: how to use where parameter?

Communicator

My logs are showing on splunk like given below -

INFO [main] 05-21 10:00:53 Fetching 0 messages. Total 0 messages. (Reading.java:270)

0 Karma
Highlighted

Re: how to use where parameter?

Motivator

You want to place the where clause after your stats count. Like so:

eventtype="email_fetching" Fetching  | stats count | where count>80

Hope this helps

View solution in original post

Highlighted

Re: how to use where parameter?

Communicator

thanks buddy.. It works..

0 Karma
Highlighted

Re: how to use where parameter?

Motivator

Hello! Put the where clause after the count.

    eventtype="email_fetching" Fetching| stats count as totalcount | where totalcount>80 

Thanks

Highlighted

Re: how to use where parameter?

Communicator

thanks buddy.. It works..

0 Karma