I have a period field which is showing a monthly count.
I am using | stats count by Period
But, I am getting a count by every month. I need total count of events per year
You could extract year from your period field.. Not sure what's the formal of period value but you can simply use combination of substr and mvindex to do this. Then can do |stats count by . Depending on use case you could also use the inbuilt interesting field called date_year to do the count.
Hope this helps
Cheers
Hi,
there is a field called date_year automatically extracted by splunk if your sourceype is configured correctly. You can use this field with stats. In your case | stats count by date_year
Greetings,
Tom