Splunk Search

Perform stats on full data and deduplicated data

Bulluk
Path Finder

Hi

I need to present a simple couple of counts on some IIS logs. One count will be raw, total hits, the other will be deduplicated by the user to show unique users. The following 2 commands work individually:

"search to return the data" | stats count as TotalHits by cs_uri_stem | table cs_uri_stem, TotalHits 

"search to return the data" | dedup cs_username | stats count as UniqueHits by cs_uri_stem | table cs_uri_stem, UniqueHits 

however I get no results when I bring them togther. I presume this is because the stats command throws columns away but I'm not sure how to overcome it.

"search to return the data" | stats count as TotalHits by cs_uri_stem | dedup cs_username | stats count as UniqueHits by cs_uri_stem | table cs_uri_stem, TotalHits , UniqueHits 

Thanks in advance

Tags (2)
0 Karma
1 Solution

Ayn
Legend

If all you want from the second search is to get a distinct usercount, just use distinct_count or dc which is the short form:

... | stats count as TotalHits,dc(cs_username) as UniqueHits by cs_uri_stem | table cs_uri_stem TotalHits UniqueHits

View solution in original post

0 Karma

Ayn
Legend

If all you want from the second search is to get a distinct usercount, just use distinct_count or dc which is the short form:

... | stats count as TotalHits,dc(cs_username) as UniqueHits by cs_uri_stem | table cs_uri_stem TotalHits UniqueHits
0 Karma

Bulluk
Path Finder

It's easy when you know how 🙂

Thanks for such a quick response!

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...