Splunk Search

why this group by is not returning results?

sou128
Explorer

I've this simple search that uses BY but it's not returning any results. Without the BY clause, it's returning the correct results.

source="C:\tmp\log4j2.log" bam error errorId BY errorId

any help is appreciated, thx. I already checked the sql ref
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/SQLtoSplunk

Tags (3)
0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

You will need to use the BY operator with a stats, chart or timechart commmand.

Example only :

source="C:\tmp\log4j2.log" error bam | stats count BY errorId

View solution in original post

Damien_Dallimor
Ultra Champion

You will need to use the BY operator with a stats, chart or timechart commmand.

Example only :

source="C:\tmp\log4j2.log" error bam | stats count BY errorId

sou128
Explorer

got it.

| stats count(errorId) BY errorId

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...