Hello, I have a problem where my graphs on the dashboard are showing the field name as a counted type. (i.e. ROUTE) See picture.
There is no line that contains 'ROUTE:' in my data as I am using a CSV without headers. My headers are defined in my custom source type.
My search is: source="C:\QS1\WF_LD.CSV" | stats count by "ROUTE"
How can I remove this from the visualization?
Thanks!
source="C:\\QS1\\WF_LD.CSV" | stats count by "ROUTE"
|where isnotnull(ROUTE)
OR
|where ROUTE!=""
hi, @rxtawell
At last, why not remove the line?
and Do you check the statistics ? what's the results?
Hi,
Could you please provide the sample data for this.
Also, please try the below SPL
Please try and update us whether this works.
| source="C:\\QS1\\WF_LD.CSV"
|table ROUTE
|where isnotnull(ROUTE)
|stats count as route_count by ROUTE
source="C:\\QS1\\WF_LD.CSV" | stats count by "ROUTE"
|where isnotnull(ROUTE)
OR
|where ROUTE!=""
hi, @rxtawell
At last, why not remove the line?
and Do you check the statistics ? what's the results?
Thank you, it was as simple as |where ROUTE!=""
You told Splunk to count the literal string "ROUTE" so that is what it did.
Try source="C:\\QS1\\WF_LD.CSV" | stats count by ROUTE
Thank you for this. I tried this change but I get the same results.