Splunk is not well-known for reporting on things that don't exist, you have to give it some clues! index=printer sourcetype=printer:logs
| stats count sum(pages_printed) AS pages_printed by printer_...
See more...
Splunk is not well-known for reporting on things that don't exist, you have to give it some clues! index=printer sourcetype=printer:logs
| stats count sum(pages_printed) AS pages_printed by printer_name,
| lookup printers.csv printer_name AS printer_name OUTPUT printer_location
| table printer_name, printer_location, count, pages_printed
| append
[| inputlookup printers.cvs ``` Should this be csv? ```
| eval count = 0, pages_printed = 0
| table printer_name printer_location count pages_printed]
| stats sum(count) as count sum(pages_printed) as pages_printed by printer_name printer_location
| rename printer_name AS "Printer Name", printer_location AS "Location", count AS "Print Job", pages_printed AS "Pages Printed"