I've this simple search that uses BY but it's not returning any results. Without the BY clause, it's returning the correct results.
source="C:\tmp\log4j2.log" bam error errorId BY errorId
any help is appreciated, thx. I already checked the sql ref
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/SQLtoSplunk
You will need to use the BY operator with a stats, chart or timechart commmand.
Example only :
source="C:\tmp\log4j2.log" error bam | stats count BY errorId
You will need to use the BY operator with a stats, chart or timechart commmand.
Example only :
source="C:\tmp\log4j2.log" error bam | stats count BY errorId
got it.
| stats count(errorId) BY errorId