I have the data field "user" with data like:
user1, user1, user2, user2, user3, user3, user3, ...
How do I get/count all items with an occurrence < 3?
Steffen
Assuming you are talking about data inside single events (otherwise you can use the answer by @gcusello), like this:
index="YouShouldAlwaysSpecifyAnIndex" AND sourctype="AndSourcetypeToo"
| makemv delim="," user
And then either:
| where mvcount(user)<3
Or:
| where mvcount(mvdedup(user))<3
Sorry, but every user/username is in one event. In the end I want to count the occurrences of this names. Thank you!
Hi steffen1,
you have only one user value for each event or do you have more values in each event?
if the first, try something like this:
index=my_index
| stats count BY user
| where count<3
Ciao.
Giuseppe
But how to count this users? Do I have to save it to a variable first?