Splunk Search

How do you write a search for an incremental count for a field evaluating success vs. failure?

karthikeyan_k14
New Member

My output is

Success
Success
Success
Failure
Failure
Faliure
Success
Success
Success
Failure
Success
Success
Success
Success
Success
Success

I need count should be

Field1 count
Success 1
Success 1
Success 1
Failure 0
Failure 0
Faliure 0
Success 2
Success 2
Success 2
Failure 0
Success 3
Success 3
Success 3
Success 3
Success 3
Success 3
...
...
...
..

Success 15
Success 15
Failure 0
Success 16
Success 16
....... like wise

currently my query is .............streamstats count(eval (Field1="Success")) as count by Field1 rest_on_change=true | table Field count

0 Karma

DalJeanis
Legend

Here's what I generally do for that, assuming the Success or Failure field is called Field1.

| streamstats current=f last(Field1) as priorField1
| eval newgroup=case(Field1="Failure",null(),   isnull(priorField1),1,   priorField1!=Field1,1)
| streamstats sum(newgroup) as groupno by Field1
| Table Field1 groupno
0 Karma
Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...