For example I have a query like below
index=ABC | stats count by host
Does stats is the word count of all the events or character count of all events or is it just the event count?
In the example above, Splunk will count the number of events per host.
View solution in original post
Yes, It is just event count.
| stats count by host will return count of events from each host for selected time range.
| stats count by host
stats command is not just for a event count It is more than that. Please refer below links for magical example for stats command.
If you'd like a count of events, words, and characters by host:
| rex max_match=0 "(?<words>\w+)"
| mvexpand words
| stats sum(eval(len(_raw))) AS character_count count(words) AS word_count count AS event_count BY host