Follow the steps in this recipe to leverage summary indexing and to backfill the number of purchases by city:
- Log in to your Splunk server.
- Select the Operational Intelligence application.
- From the search bar, enter the following search and select to run over Last 24 hours:
index=main sourcetype=log4j requestType="checkout" | iplocation ipAddress | fillnull value="Unknown" City | replace "" with "Unknown" in City | stats count AS Purchases by City
- Splunk should now display the results of the search, similar to the results shown in the following screenshot:
- Click on the Save As dropdown and select Report from the list: ...