Splunk Search

Counting Events?

MichaelCohen829
Explorer

Splunk Community,

I’d like to be able to count the number of events I have per SourceFile when my sourcetype is LogFile:

sourcetype="LogFile" SourceFile="File1”

I also have a number of other SourceFiles (“File2” , “File3” …etc…)

I’ve tried a number of things with no success as of yet – does anyone know how would I be able to count the number of events, per SourceFile within the SourceType “LogFile”?

Thank you,

Mike

Tags (2)
0 Karma
1 Solution

MuS
Legend

Hi MichaelCohen829,

try something like this:

sourcetype="LogFile" OR SourceFile="File*" | stats count by sourcetype

cheers, MuS

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Counting and filtering by metadata fields such as source and sourcetype can be done much more quickly with tstats:

| tstats count where index=yourindex sourcetype="LogFile" by source

http://docs.splunk.com/Documentation/Splunk/6.1.1/SearchReference/tstats

0 Karma

MuS
Legend

Hi MichaelCohen829,

try something like this:

sourcetype="LogFile" OR SourceFile="File*" | stats count by sourcetype

cheers, MuS

MuS
Legend

Thanks, you're welcome

0 Karma

MichaelCohen829
Explorer

Thank you MuS - this achieved exactly what I wanted!

Mike

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...