44 Views

20th June 2020

Splunk Count By Field

How can we obtain a total count and also count by the specific field shown in the same stats table?

Answers

20th June 2020

Answered by naveen nani

We can obtain a count and also count by a specific field by using the following command:

Base search | top limit=0 count by myfield showperc=t | eventstatus sum(count) as totalcount

 

Write your answer

STILL GOT QUERIES?

Get a Live FREE Demo
  • Explore the trending and niche courses and learning maps
  • Learn about tuition fee, payment plans, and scholarships
  • Get access to webinars and self-paced learning videos