Splunk Search

Perform stats on full data and deduplicated data

Bulluk
Path Finder

Hi

I need to present a simple couple of counts on some IIS logs. One count will be raw, total hits, the other will be deduplicated by the user to show unique users. The following 2 commands work individually:

"search to return the data" | stats count as TotalHits by cs_uri_stem | table cs_uri_stem, TotalHits 

"search to return the data" | dedup cs_username | stats count as UniqueHits by cs_uri_stem | table cs_uri_stem, UniqueHits 

however I get no results when I bring them togther. I presume this is because the stats command throws columns away but I'm not sure how to overcome it.

"search to return the data" | stats count as TotalHits by cs_uri_stem | dedup cs_username | stats count as UniqueHits by cs_uri_stem | table cs_uri_stem, TotalHits , UniqueHits 

Thanks in advance

Tags (2)
0 Karma
1 Solution

Ayn
Legend

If all you want from the second search is to get a distinct usercount, just use distinct_count or dc which is the short form:

... | stats count as TotalHits,dc(cs_username) as UniqueHits by cs_uri_stem | table cs_uri_stem TotalHits UniqueHits

View solution in original post

0 Karma

Ayn
Legend

If all you want from the second search is to get a distinct usercount, just use distinct_count or dc which is the short form:

... | stats count as TotalHits,dc(cs_username) as UniqueHits by cs_uri_stem | table cs_uri_stem TotalHits UniqueHits
0 Karma

Bulluk
Path Finder

It's easy when you know how 🙂

Thanks for such a quick response!

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...