Splunk Search

Why is stats count by fieldname not working?

pchava
New Member

In search getting list of events and stats giving count of events but when extend the search by field name, throwing "No results yet found" error.

Am I doing anything wrong?

0 Karma
1 Solution

PowerPacked
Builder

Hi @pchava

Check if the field is extracted or not, & are you able to see the field in the list of fields ( Selected Fields & Interesting Fields) on the left handed side

Thanks

View solution in original post

0 Karma

PowerPacked
Builder

Hi @pchava

Check if the field is extracted or not, & are you able to see the field in the list of fields ( Selected Fields & Interesting Fields) on the left handed side

Thanks

0 Karma

pchava
New Member

Hi @PowerPacked,
Its extracted, I can see in Interesting fields (even i tried by moving field from interesting to selected fields).

Thanks.

0 Karma

pchava
New Member

Hi @powerpacked, its working thanks, my bad I missed case sensitive for the field names.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...