Splunk Search

How to create a search that will show other fields like dest_bunit with the port?

jregexsaurus
Engager

This search will display port numbers from the Endpoint datamodel

| tstats 'summariesonly ' count from datamodel=EndPoint.Port.dest_port 

I would like to create a search that will show other fields like dest_bunit with the port.

Without the datamodel I could just do a stats count by dest port.  I'm not sure how to replicate this query using the datamodel. 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The syntax may not be exactly right, but have you tried something like this?

| tstats `summariesonly` count, values(Endpoint.Port.dest_bunit) as dest_bunits from datamodel=EndPoint.Port.dest_port 
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The syntax may not be exactly right, but have you tried something like this?

| tstats `summariesonly` count, values(Endpoint.Port.dest_bunit) as dest_bunits from datamodel=EndPoint.Port.dest_port 
---
If this reply helps you, Karma would be appreciated.

VatsalJagani
SplunkTrust
SplunkTrust

Or this:

| tstats `summariesonly` count as dest_bunits from datamodel=EndPoint.Port by Endpoint.Port.dest_port, Endpoint.Port.dest_bunit

If not, try below:

| tstats `summariesonly` count as dest_bunits from datamodel=EndPoint.Port by Port.dest_port, Port.dest_bunit

  

I hope this helps!!!

Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...