Try the following run anywhere example. You can use <progress>
or <done>
search event handler depending on your use case to capture the number of results returned by a search using a predefined token $job.resultCount$
<dashboard>
<label>Table Result Count</label>
<row>
<panel>
<title>My Search (Results: $tokResultCount$)</title>
<table>
<search>
<query>index=_internal sourcetype=splunkd
| stats count by component
</query>
<earliest>-1h@h</earliest>
<latest>now</latest>
<progress>
<set token="tokResultCount">$job.resultCount$</set>
</progress>
</search>
</table>
</panel>
</row>
</dashboard>
Refer to documentation: https://docs.splunk.com/Documentation/Splunk/latest/Viz/tokens#Search_event_elements_and_job_propert...
@ronniemakhombi the expected output is still not clear. For the community to assist you better please add further details as to which value is the total and where is it going to be displayed. Also whether this request is for Dashboard or not?
Thank you for your comment, I want to display the total number of events/records. for example in the snippet attached, there are five records (5). Is there a way i can print this out or display this number.
Do you want total of ACC_NBR column?
Thank you for your comment, I want to display the total number of events/records. for example in the snippet attached, there are five records (5). Is there a way i can print this out or display this number.
Can you try :
| stats count by ACC_NBR
@ronniemakhombi
you can go with my code|dedup ACC_NBR |stats count
No, I want to print or display 86 513 for reporting
@ronniemakhmbi
add end of your query like this
|dedup ACC_NBR |stats count