Splunk Community,
I’d like to be able to count the number of events I have per SourceFile when my sourcetype is LogFile:
sourcetype="LogFile" SourceFile="File1”
I also have a number of other SourceFiles (“File2” , “File3” …etc…)
I’ve tried a number of things with no success as of yet – does anyone know how would I be able to count the number of events, per SourceFile within the SourceType “LogFile”?
Thank you,
Mike
Hi MichaelCohen829,
try something like this:
sourcetype="LogFile" OR SourceFile="File*" | stats count by sourcetype
cheers, MuS
Counting and filtering by metadata fields such as source
and sourcetype
can be done much more quickly with tstats
:
| tstats count where index=yourindex sourcetype="LogFile" by source
http://docs.splunk.com/Documentation/Splunk/6.1.1/SearchReference/tstats
Hi MichaelCohen829,
try something like this:
sourcetype="LogFile" OR SourceFile="File*" | stats count by sourcetype
cheers, MuS
Thanks, you're welcome
Thank you MuS - this achieved exactly what I wanted!
Mike