Executes one or more aggregation on each row group.
stats [parallel=BOOL] AGGR_FUNC [as ALIAS], ... [by GRP_FIELD, ...]
AGGR_FUNC [as ALIAS], ...
- Name of a group function (
AGGR_FUNC) and optional alias (
ALIAS) as a field name. If no alias is provided, the command uses the function name as the field name, such as count() and sum(sent_pkts). It is recommended that you specify an
- Option to enable parallel processing (default:
t: Enables processing the query in parallel. The processing speed increases but the order of data is not guaranteed. Avoid using this option in query commands where the order of the data matters. Avoid using this option in query commands where the order of the data matters.
f: Disables processing the query in parallel.
by GRP_FIELD, ...
- Grouping fields with
bydirective, separated by a comma(
Return the number of rows.
Return the number of rows for each value of src_ip field.
stats count by src_ip
Return the number of rows by grouping it into pairs of src_ip and dst_ip fields.
stats count by src_ip, dst_ip
stats sum(bytes) as bytes, count by src_ip, dst_ip