I have a transaction with multiple values for the same field. Is it possible for me to do a dc(other_field) within a transaction?
My search | transaction same_field maxspan=1m | stats dc(other_field)
Above doesn't seem to work, it just throws away my transactions.
I think mvcount() could be your friend here. Something along these lines:
your search | transaction same_field maxspan=1m | eval same_field_count=mvcount(same_field)
...something like that. same_field_count should be a count of the distinct values of same_field within each transaction. If you want a total count of ALL values of same_field (including duplicates) within each transaction, use the mvlist option within your transaction. I'm not where I can test this search but I think it will be pretty close to what you need.
I think mvcount() could be your friend here. Something along these lines:
your search | transaction same_field maxspan=1m | eval same_field_count=mvcount(same_field)
...something like that. same_field_count should be a count of the distinct values of same_field within each transaction. If you want a total count of ALL values of same_field (including duplicates) within each transaction, use the mvlist option within your transaction. I'm not where I can test this search but I think it will be pretty close to what you need.
I dont believe mvcount returns a count of the distinct values. It simply returns a count of the number of values
Sure, happy to help!
Yes! Thank you!!
eventstats
perhaps?