Splunk Search

How to filter my search to only count the users that visited each location at least N number of times?

pm771
Communicator

We have a listing of travelers. Every event has the following two fields: USER and LOCATION.

I need a search that will calculate how many frequent travelers visited each location. By definition, frequent traveler is a user that traveled in a given time period at least n times.

If I wanted just a grand total of such users, then I would've written it as:

index=... sourcetype=... | stats count as num by USER | where num > n | stats count as Total

How do I restore an association between selected users and their respective locations?

It sounds like a job for eventstats but I could not come up with a working search.

0 Karma
1 Solution

sundareshr
Legend

See if this gets you what you need

 index=... sourcetype=... | eventstats count as num by USER | where num > n | stats dc(USER) as FT by LOCATION

View solution in original post

sundareshr
Legend

See if this gets you what you need

 index=... sourcetype=... | eventstats count as num by USER | where num > n | stats dc(USER) as FT by LOCATION

pm771
Communicator

Actually my requirements were: how many times frequent travelers visited each location, so I dd not need distinct count.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...