Splunk Search

Simple query to take results and list them as yes/no

mflippin
New Member

Hello. 

I have a large data set that I'm working through that gives either a 5 digit number or a "-" if there is no value. I have my search results but I can't seem to get them into the format I'm looking for. 

I'd like to get the results into a format showing

Room 1 

Set (total)

Unset (total)

And the same for Room 2, 3, 4

 

Query

Index=acme dvc_room="*" station="*" 

Output 

index=acme dvc_room=4 station="-"

index=acme dvc_room=3 station="123456"

index=bluecoat dvc_room=2 station="-"

index=bluecoat dvc_room=1 station="56132"

index=bluecoat dvc_room=3 station="-"

index=bluecoat dvc_room=2 station="56132"

index=bluecoat dvc_room=4 station="56132"

 

Any help would be appreciated. 

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

You say your query is 

Index=acme dvc_room="*" station="*" 

but you list output with index=bluecoat

Maybe this is what you are after

your search...
| stats sum(eval(if(station="-",0,1))) as Set sum(eval(if(station="-",1,0))) as Unset by dvc_room

Assuming that when you talk about set/unset, you mean that unset is station="-" and set if not.

 

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...