Hello,
I have a set of data similar to this :
session1 | user1 | computer 1 | start
session2 | user2 | computer 2 | start
session1 | user1 | computer 1 | stop
session2 | user2 | computer 2 | stop
session1 | user1 | computer 1 | start
session3 | user3 | computer 3 | start
I would like to count the number of starts and stops for each session.
session1 | user1 | computer 1 | 2 | 1
session2 | user2 | computer 2 | 1 | 1
session3 | user3 | computer 3 | 1 | 0
Thank you for your help
Try something like this:
[YOUR BASE SEARCH HERE]
| stats count(eval(action="start")) as starts count(eval(action="stop")) as stops by session user computer
I created a field called action for start and stop values, as well as giving the other fields logical names: session; user; and computer.
Try something like this:
[YOUR BASE SEARCH HERE]
| stats count(eval(action="start")) as starts count(eval(action="stop")) as stops by session user computer
I created a field called action for start and stop values, as well as giving the other fields logical names: session; user; and computer.
I just realized my search was a bit off based on your request. You wanted to know the number of starts and stops per session. That would look more like the following:
[YOUR BASE SEARCH HERE]
| stats count(eval(action="start")) as starts count(eval(action="stop")) as stops values(user) as users values(computer) as computers by session
The users and computers fields would have a multivalued list of all distinct values for the user and computer fields. Not sure if that is what you wanted, but probably a good idea since there would be multiple values based on your data sample.
That's exactly what I was looking for ; Thank you very much