Splunk Search

unique values

rcbutterfield
Explorer

Hello Splunk People....

I want to return a search within splunk.  THe index is wineventlogs and i want to return all the eventcodes within eventtypes.  

Meaning.... 

Eventtype A includes eventcode 5144, 5145, 5146

Eventtype b includes eventcode 5144, 5166, 5167

As examples....   thanks to all

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @rcbutterfield ,

you should try something like this:

index=wineventlog
| stats
     values(EventCode) AS EventCode
     count
     By eventtype

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @rcbutterfield ,

you should try something like this:

index=wineventlog
| stats
     values(EventCode) AS EventCode
     count
     By eventtype

Ciao.

Giuseppe

rcbutterfield
Explorer

Thank you!  it works perfect! 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rcbutterfield ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...