Post
Splunk
How can we obtain a total count and also count by the specific field shown in the same stats table?
Posted on 4th August 2023
We can obtain a count and also count by a specific field by using the following command:
Base search | top limit=0 count by myfield showperc=t | eventstatus sum(count) as totalcount
STILL GOT QUERIES?
Copyright © 2013 - 2023 MindMajix Technologies