Splunk Search

Equivalent of using an eval inside a stats sum(count)?

Lucas_K
Motivator

I have the following search used to gather data which is used later in a hiddenpostprocess search :

index=blah | stats count by Product_Group, Application, Severity, _time

My postprocessing seach is :

stats sum(count) AS Count by Product_Group Severity 

Which outputs the data in a multiline per product format.
ie.

Product_Group Severity Count
A   Major   1
B   Major   1
C   Major   6
C   Minor   1
D   Minor   2
E   Minor   1
F   Critical 92
F   Major   117

3 columns. Product_group Severity and count.

I would like to format the data like this.

Product_Group Critical Major Minor
A 0 1 0
B 0 1 0
C 0 6 1
D 0 0 2
E 0 0 1
F 92 117 0

Prior to using postprocessing a search that would provides the format I want would be :

stats sum(eval(Severity="Critical")) AS Critical, sum(eval(Severity="Major")) AS Major, sum(eval(Severity="Minor")) AS Minor by Product_Group | sort - num(Critical)

Is it possible to use an eval within a stats sum(count)?
Anytime I try to do an eval inside that I get zero values.

edit #1: Tried using a chart command

| stats sum(count) AS Count by Product_Group Severity | chart Count over Product_Group by Severity

But it is not fed the correct data so its wrong (but right visual format however!).

Tags (4)
1 Solution

Lucas_K
Motivator

i was close with my first edit.

The solution for those playing at home.

chart sum(count) AS Count over Product_Group by Severity

So simple facepalm.

View solution in original post

Lucas_K
Motivator

i was close with my first edit.

The solution for those playing at home.

chart sum(count) AS Count over Product_Group by Severity

So simple facepalm.

Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...