Splunk Enterprise Security

Distinct Count combined with List

jacqu3sy
Path Finder

Is it possible to take a distinct count of something, then list this by an additional value by day?

something like the following but tweaked to display the count of events, by urgency on specific days;

notable
| bucket _time span=1d
| stats dc(event_id) by urgency, _time

The goal being a table that looks like the following;

Monday Medium, 5
High, 7
Tuesday Low, 6
Medium, 10
High, 20
etc etc

Thanks.

0 Karma
1 Solution

to4kawa
Ultra Champion
notable
| bucket _time span=1d
| chart dc(event_id) by date_wday urgency
| table date_wday, High, Medium, Low

Hi, @jacqu3sy
Please use chart.
Finally, the order of the columns must be aligned.

View solution in original post

0 Karma

to4kawa
Ultra Champion
notable
| bucket _time span=1d
| chart dc(event_id) by date_wday urgency
| table date_wday, High, Medium, Low

Hi, @jacqu3sy
Please use chart.
Finally, the order of the columns must be aligned.

0 Karma

jacqu3sy
Path Finder

great stuff. Many thanks.

0 Karma

TISKAR
Builder

Hi @jacqu3sy:

can you try this please:

notable
| bucket _time span=1d
| stats dc(event_id) by date_wday, urgency
0 Karma

jacqu3sy
Path Finder

Kinda, but I want to list the results for each day within it's own row, if that makes sense.

So that is display better, in a table with a row for Monday, then alongside it listed the count by urgency.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...