Hello,
I'm new with splunk and I'm trying to get all the different values of a field with stats values() command with results grouped by another field. Here is the query:
src=* | eval src_act=src.".".act | stats values(vendor) as vendors dc(vendor) as num_vendors by src_act | where num_vendors>1
The maximum number of vendors returned by the query is two, but searching with the "view events" link of a result, the real number of different vendors is three or four in some cases.
The same problem occurs using the list() function, it only shows the elements from a maximum of two different vendors.
I tried to modify the list_maxsize param in limits.conf file but it doesn't solve the problem, even with the list() function, no more that 2 different values in "vendors" field.
Anybody can help me?
Thank you very much!
Regards.
... View more