Splunk Search

date_month issue

iamniks
Explorer

"source="jun_jan.csv" | stats count by date_month" lists all months, but if I want to include another field like status ""source="jun_jan.csv" | stats count by date_month, STATUS" It lists only two months. Plese suggest how do we get the other field

source="jun_jan.csv" | stats count by date_mont
date_month count

1 august 2776
2 december 4602
3 january 5228
4 july 3533
5 november 5001
6 october 3357
7 september 4275

source="jun_jan.csv" | stats count by date_month, STATUS
date_month STATUS count

1 august FAILED 262
2 august PASSED 2046
3 august WARNING_FAILED_STEP 23
4 august WARNING_FILTER 14
5 july FAILED 433
6 july NONE 1
7 july PASSED 3002
8 july WARNING_FAILED_STEP 76
9 july WARNING_FILTER 21

Tags (3)
0 Karma

ziegfried
Influencer

Look at the events that are in months, not displayed in the second result and see if the STATUS field is present there. The search ... | stats count by date_month,STATUS will only show the result counts for events with both fields present.

0 Karma

ziegfried
Influencer

is there a date_month field too for all of them?

0 Karma

iamniks
Explorer

For all the events there is a status as well as process field,

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...