Splunk Search

combining 2 stats output into 1

p_basanth
New Member

I want to combine the below 2 ouputs into single line

| stats count by Domain

| stats values(Domain) by Short_Host

The expected output is

Short_Host Values(Domain) Count by Domain

Tags (1)
0 Karma

royimad
Builder

You can combine several line with "," and count for a specific values
| stats count(eval(Domain="y")) , count(eval(Domain="x")) by Short_Host

0 Karma

p_basanth
New Member

| stats values(Domain), count by Short_Host gives me overall count. But i need individual count by Domain.

0 Karma

p_basanth
New Member

something similar to values,count group by short_host. For each short_host multiple domains and corresponding count in a table format.

0 Karma

p_basanth
New Member

Apologies. My expectation is as per below:
Short_Host Values(Domain) Count by Domain
host 1 abc 11
xyz 15
def 20
host 2 abc 06
xyz 27
def 34

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...