Splunk Search

combining 2 stats output into 1

p_basanth
New Member

I want to combine the below 2 ouputs into single line

| stats count by Domain

| stats values(Domain) by Short_Host

The expected output is

Short_Host Values(Domain) Count by Domain

Tags (1)
0 Karma

royimad
Builder

You can combine several line with "," and count for a specific values
| stats count(eval(Domain="y")) , count(eval(Domain="x")) by Short_Host

0 Karma

p_basanth
New Member

| stats values(Domain), count by Short_Host gives me overall count. But i need individual count by Domain.

0 Karma

p_basanth
New Member

something similar to values,count group by short_host. For each short_host multiple domains and corresponding count in a table format.

0 Karma

p_basanth
New Member

Apologies. My expectation is as per below:
Short_Host Values(Domain) Count by Domain
host 1 abc 11
xyz 15
def 20
host 2 abc 06
xyz 27
def 34

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...