Original Data
SrcIP SrcName DstIP DstName DstPort
192.168.1.1 bob.net.net 172.16.16.1 alice.net.net 21
192.168.1.1 bob.net.net 172.16.16.1 alice.net.net 21
Data that I would like to Display
SrcIP SrcName DstIP DstName DstPort Count
192.168.1.1 bob.net.net 172.16.16.1 alice.net.net 21 2
Ok... wow, that was much easier than I thought. Thanks for helping me, and making me feel more than a little silly.
No problem 🙂 That's often the case with Splunk - seemingly difficult task can be solved surprisingly easy by finding the right command and arguments!
Could you please mark my answer as accepted? Thanks!
... | stats count by SrcIP SrcName DstIP DstName DstPort