For example I have a query like below
index=ABC | stats count by host
Does stats is the word count of all the events or character count of all events or is it just the event count?
In the example above, Splunk will count the number of events per host.
Hi @pavanae,
Yes, It is just event count.
| stats count by host
will return count of events from each host for selected time range.
stats
command is not just for a event count It is more than that. Please refer below links for magical example for stats
command.
http://docs.splunk.com/Documentation/Splunk/7.0.1/SearchReference/Stats
https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Stats
Thanks
Kamlesh
In the example above, Splunk will count the number of events per host.
If you'd like a count of events, words, and characters by host:
index=ABC
| rex max_match=0 "(?<words>\w+)"
| mvexpand words
| stats sum(eval(len(_raw))) AS character_count count(words) AS word_count count AS event_count BY host