Splunk Search

Consolidating portion of a field before counting

spetzd1
Engager

So, I have a very basic report I am trying to generate that takes an extracted field called MatchesFound and sums up how many of each value it sees:

...| stats count as total by MatchesFound

The result looks something like:

MatchesFound  |   total
1             |    34
2             |    15
3             |    12
5             |    7
6             |    1
7             |    4
9             |    6

The problem I have is that I would like to group some of the MatchesFound together, so that the list goes from 1 through 5 and then has every MatchCount of 6 or higher grouped together. The final table should look something like:

MatchesFound  |   total
1             |    34
2             |    15
3             |    12
5             |    7
6  +          |    11
0 Karma
1 Solution

somesoni2
Revered Legend

Try something like this

...| stats count as total by MatchesFound | eval MatchesFound=if(MatchesFound>=6,"6+",MatchesFound)  | stats sum(total) as total by MatchesFound

View solution in original post

somesoni2
Revered Legend

Try something like this

...| stats count as total by MatchesFound | eval MatchesFound=if(MatchesFound>=6,"6+",MatchesFound)  | stats sum(total) as total by MatchesFound

spetzd1
Engager

Worked like a charm. Thank you!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...