Splunk Command: FIELDSUMMARY
Field summary calculates field summary for one or more fields available in our event.
Syntax:
| fieldsummary [maxvals=<unsigned_int>] [fields=”[“<wc-field-list>”]” ]
There are no required arguments available with this command.
Function:
The fieldsummary command calculates summary statistics, such as
- The count,
- Maximum value,
- Minimum value,
- Mean, and
- Standard deviation
for the fields in your search results. These summary statistics are displayed in a table for each field in your results or for the fields, you specify with the fieldsummary command.
Example:
index=_internal
| fieldsummary
Result:
Explanation:
Here as you can see this is a pretty simple command. After using this command we can get all the fields available not just the field all the statical calculations of that field.
I hope you all have enjoyed this blog “Splunk Command: FIELDSUMMARY“. See you all on to the next one.
Happy Splunking!!