This may be simple, but I am pretty new to splunk in general and my attempts have not proved fruitful yet.
So I have a search returns a timechart of distinct users per State for an event, works fine. Timechart auto breaks it down which can be tuned, no problems there. What I want to do though, is add one final line to my timechart that is a "cumulative distinct count" for the search. The catch is, I want it to be a DC for the WHOLE timeframe, not just a sum of each dc timechart splits up into (aka addtotals col=t is not what I am looking for).
Any thoughts?
Edit: Here is the search string
PS: I am having a TERRIBLE time with captchas on this site, worst ever... I can't edit my original post, always fails.
I think you are looking for
...| eventstats dc(users) | ...
Or something similar, please add your base search and sample events to get more information