Getting Data In

many events for each user - how to see only one event from each user?

rechteklebe
Path Finder

Hello together,

i would like to see in a search the amount of affected user. Sometimes there are more events related to one user (e.g. user=12345).

I search for example for: index=123 ERROR user=*

Now i would like to see the amount of user who are affected. How can i not showing duplicate events of one user. I would like to see only one event from each user.

e.g

There are 7 events for user=12345

There are 7 events for user=23456



--> I would like to see only:

1 event for user 12345

1 event for user 23456

Please help me.

Thank you in advance!

Tags (2)
0 Karma
1 Solution

Ayn
Legend
Get Updates on the Splunk Community!

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...