{"id":69501,"date":"2023-01-10T21:10:58","date_gmt":"2023-01-10T21:10:58","guid":{"rendered":"https:\/\/merikebi.warrenmyers.com\/?p=69501"},"modified":"2023-01-10T21:10:58","modified_gmt":"2023-01-10T21:10:58","slug":"a-rich-mans-fieldsummary","status":"publish","type":"post","link":"https:\/\/merikebi.warrenmyers.com\/?p=69501","title":{"rendered":"a rich man\u2019s fieldsummary"},"content":{"rendered":"<p>The Splunk command <a href=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/latest\/SearchReference\/fieldsummary\"><code>fieldsummary<\/code><\/a> is amazing &#8211; I use it quite frequently to explore more &#8220;new&#8221; (to me) sourcetypes, and to find out about more fields than I&#8217;ve previously used in the sourcetypes I work with most.<\/p>\n<p>But sometimes you want to be able to delineate more granularly than <code>fieldsummary<\/code> will allow.<\/p>\n<p>Maybe you have a single <a href=\"https:\/\/docs.splunk.com\/Splexicon:Sourcetype\">sourcetype<\/a> that happens to have a couple variations (<a href=\"https:\/\/smile.amazon.com\/s\/?tag=antipaucity-20&#038;creative=392009&#038;campaign=212361&#038;field-keywords=Forescout CounterACT\">Forescout CounterACT<\/a> data is like this (it&#8217;s all <a href=\"https:\/\/smile.amazon.com\/s\/?tag=antipaucity-20&#038;creative=392009&#038;campaign=212361&#038;field-keywords=JSON\">JSON<\/a>, but there are ways to distinguish events based on the field <code>ctupdate<\/code>)).<\/p>\n<p>What is a <a href=\"https:\/\/smile.amazon.com\/s\/?tag=antipaucity-20&#038;creative=392009&#038;campaign=212361&#038;field-keywords=Splunk\">Splunk<\/a> user to do?<\/p>\n<p>Try this:<\/p>\n<pre class=\"wp-block-code\"><code>index=ndx sourcetype=srctp &lt;field_to_split_on>=*\n| fields - _raw index sourcetype\n| foreach *\n    &#91; eval &lt;&lt;FIELD>> = mvindex('&lt;&lt;FIELD>>',0) ]\n| stats latest(*) as * by &lt;field_to_split_on>\n| transpose 0 header_field=&lt;field_to_split_on>\n| rename column as field<\/code><\/pre>\n<p>Run this in <a href=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/latest\/Search\/Changethesearchmode\">Verbose mode<\/a> over a long enough time window to capture what you want to see (at one customer, I could pick <code>earliest=-20m<\/code> and have an <strong>ample<\/strong> sample).<\/p>\n<p>I&#8217;m removing the fields <code>_raw<\/code>, <code>index<\/code>, and <code>sourcetype<\/code> because I &#8220;know&#8221; the index and sourcetype, and <code>_raw<\/code> just isn&#8217;t that helpful in this context.<\/p>\n<p>from antipaucity https:\/\/antipaucity.com\/2023\/01\/10\/a-rich-mans-fieldsummary\/<br \/>\nvia <a href=\"https:\/\/ifttt.com\/?ref=da&#038;site=wordpress\">IFTTT<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Splunk command fieldsummary is amazing &#8211; I use it quite frequently to explore more &#8220;new&#8221; (to me) sourcetypes, and to find out about more fields than I&#8217;ve previously used in the sourcetypes I work with most. But sometimes you want to be able to delineate more granularly than fieldsummary will allow. Maybe you have &hellip;<br \/><a href=\"https:\/\/merikebi.warrenmyers.com\/?p=69501\" class=\"more-link pen_button pen_element_default pen_icon_arrow_double\">Continue reading <span class=\"screen-reader-text\">a rich man\u2019s fieldsummary<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[4],"tags":[95],"keyring_services":[],"class_list":["post-69501","post","type-post","status-publish","format-standard","hentry","category-blih","tag-antipaucity"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/69501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=69501"}],"version-history":[{"count":1,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/69501\/revisions"}],"predecessor-version":[{"id":69502,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=\/wp\/v2\/posts\/69501\/revisions\/69502"}],"wp:attachment":[{"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=69501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=69501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=69501"},{"taxonomy":"keyring_services","embeddable":true,"href":"https:\/\/merikebi.warrenmyers.com\/index.php?rest_route=%2Fwp%2Fv2%2Fkeyring_services&post=69501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}