stats count(fieldname), not the other way around. The function always comes first in SPL stats. If the field exists in the event, it'll get counted. Pretty confident but open to pushback if anyone's seen otherwise.Q: 18
What is the correct syntax to count the number of events containing a vendor_action field?
Options
Discussion
Option C
Its B. I think count stats (vendor_action) is how I did it before in Splunk, maybe a syntax trick here.
Seriously, Splunk's syntax trips up so many on these! It's C for sure. Gotta remember it's
Probably C here
Nah, pretty sure it's B. That's the syntax I've used in some older dashboards to pull counts for fields like vendor_action.
C tbh, had something similar in a mock test and that's what worked.
Be respectful. No spam.
Question 18 of 30