Splunk Enterprise

Count number of events by a value(ServiceName) in log file

vineetc
Engager

I want to count number of events in the log file based on a serviceName and then plot them with Counts by ServiceName

Sample LogFile:

<Timestamp> Invoked Service1
<Timestamp> Invoked Service2
<Timestamp> Invoked Service3
<Timestamp> Invoked Service3
<Timestamp> Invoked Service1
<Timestamp> Invoked Service2
<Timestamp> Invoked Service1

I should get the count of invocation by service

Tags (1)
0 Karma

somesoni2
Revered Legend

If the field ServiceName is already extracted try this

your base search | stats count by ServiceName

OR

your base search | timechart count by ServiceName
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...