Splunk Search

group fields

visa87
Explorer

I have extracted a numeric field and I want to count the fields by grouping them based on the range .
For eg:

Field A
1
4
6
10
15
26
29....

Result should look like something below :
Field A - Range Count
1-10 4
11-20 1
21-30 2

Can this be achieved ?

Tags (1)
0 Karma

mmccul
SplunkTrust
SplunkTrust

Look at http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Bucket

There are examples of almost exactly what you want.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...