Hi Team,
My Query : index=*** kubernetes.container_name=*** cluster_id=*** "Number of Files Found"
Result will be like : Number of Files Found 2(or any number)
I need to get that number value alone, when it is > 0 the count have to be displayed as any chart. How can I edit my query to get like that. Do we have any option for that? Please suggest.
Thanks!
Hi @aasabatini the count of the log will always be > 0. Here I basically would like to split the log statement so as to get the number alone.
Hi @Suganya_S
if you see my example search there is a where condition to force to select the count > 0
where count > 0
Hi @Suganya_S
try to use stats comand
https://docs.splunk.com/Documentation/Splunk/8.1.3/SearchReference/Stats
index=*** kubernetes.container_name=*** cluster_id=*** "Number of Files Found" | stats count | where count > 0