Post

SplunkSplunk

j
jordan chris

Posted on 19th April 2024|1129 views

0
votes

Splunk Count By Field

How can we obtain a total count and also count by the specific field shown in the same stats table?

Answers
P
naveen nani

Posted on 19th April 2024

We can obtain a count and also count by a specific field by using the following command:

Base search | top limit=0 count by myfield showperc=t | eventstatus sum(count) as totalcount

 

Write your answer

STILL GOT QUERIES?

Get a Live FREE Demo
  • Explore the trending and niche courses and learning maps
  • Learn about tuition fee, payment plans, and scholarships
  • Get access to webinars and self-paced learning videos