Getting Data In

many events for each user - how to see only one event from each user?

rechteklebe
Path Finder

Hello together,

i would like to see in a search the amount of affected user. Sometimes there are more events related to one user (e.g. user=12345).

I search for example for: index=123 ERROR user=*

Now i would like to see the amount of user who are affected. How can i not showing duplicate events of one user. I would like to see only one event from each user.

e.g

There are 7 events for user=12345

There are 7 events for user=23456



--> I would like to see only:

1 event for user 12345

1 event for user 23456

Please help me.

Thank you in advance!

Tags (2)
0 Karma
1 Solution

Ayn
Legend
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...