Splunk Search

Do I have to turn count and if on like we have to do with delete?

BITSIntern
Path Finder

Hi guys,

I am having some trouble trying to do a search. I want to do a search that involves the tools count and if but it keeps giving me an error like: Unknown search command 'count'. When I wanted to delete a few things from my index, I had to go to my access controls and turn on the delete command but when I went back I did not see anything about other command functions.

Am I doing something wrong or do I need to turn the tools on?

Please let me know!

Tags (4)
0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

count and if are not commands. Stats and eval are, and those use count and if.

so....

<your_search> | stats count by sourcetype

That will get you started.

http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial

0 Karma

BITSIntern
Path Finder

Sorry I did not know there was a search manual.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...