<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: stats dc behavior against a summary index in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/stats-dc-behavior-against-a-summary-index/m-p/80798#M807</link>
    <description>&lt;P&gt;You are &lt;EM&gt;WAY&lt;/EM&gt;  off track here!  Think about what you are doing.  Is it proper to do dc(dc(anything))?  Once you do &lt;CODE&gt;dc&lt;/CODE&gt; on anything that is rolled up into a summary index, the only way you can rollup again, is to do something like &lt;CODE&gt;avg(dcField)&lt;/CODE&gt; or &lt;CODE&gt;mean(dcField)&lt;/CODE&gt;, etc.  You cannot (with any valid output) take an hourly dc(users) and sum(hourlyUsers) for the last 24 hours and get a daily dc(users); it is a one-way ticket: once you go the &lt;CODE&gt;dc&lt;/CODE&gt; route, you &lt;EM&gt;must not ever&lt;/EM&gt; roll those values up again (even if SPL allows it).&lt;/P&gt;</description>
    <pubDate>Fri, 29 May 2015 20:39:20 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-05-29T20:39:20Z</dc:date>
    <item>
      <title>stats dc behavior against a summary index</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/stats-dc-behavior-against-a-summary-index/m-p/80797#M806</link>
      <description>&lt;P&gt;So I have a summary index that was populated hourly with something like:&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;sourcetype="foo" | sistats count dc(s) by d&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I can then do this:&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;index="summary_foo_hourly" | stats dc(s)&lt;/CODE&gt;&lt;BR /&gt;&lt;BR /&gt;
but I cannot do this:&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;index="summary_foo_hourly" | stats dc(d)&lt;/CODE&gt;&lt;BR /&gt;&lt;BR /&gt;
nor this:&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;index="summary_foo_hourly" | stats dc(s) dc(d)&lt;/CODE&gt;&lt;BR /&gt;&lt;BR /&gt;
as dc(d) always returns zero.  &lt;/P&gt;

&lt;P&gt;Any reason this shouldn't work?&lt;/P&gt;

&lt;P&gt;I can get around it like so:&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;index="summary_foo_hourly" | stats values(s) as s by d | stats dc(s) dc(d)&lt;/CODE&gt;&lt;BR /&gt;&lt;BR /&gt;
but that's kind of a drag.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2011 16:48:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/stats-dc-behavior-against-a-summary-index/m-p/80797#M806</guid>
      <dc:creator>vbumgarner</dc:creator>
      <dc:date>2011-09-23T16:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: stats dc behavior against a summary index</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/stats-dc-behavior-against-a-summary-index/m-p/80798#M807</link>
      <description>&lt;P&gt;You are &lt;EM&gt;WAY&lt;/EM&gt;  off track here!  Think about what you are doing.  Is it proper to do dc(dc(anything))?  Once you do &lt;CODE&gt;dc&lt;/CODE&gt; on anything that is rolled up into a summary index, the only way you can rollup again, is to do something like &lt;CODE&gt;avg(dcField)&lt;/CODE&gt; or &lt;CODE&gt;mean(dcField)&lt;/CODE&gt;, etc.  You cannot (with any valid output) take an hourly dc(users) and sum(hourlyUsers) for the last 24 hours and get a daily dc(users); it is a one-way ticket: once you go the &lt;CODE&gt;dc&lt;/CODE&gt; route, you &lt;EM&gt;must not ever&lt;/EM&gt; roll those values up again (even if SPL allows it).&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2015 20:39:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/stats-dc-behavior-against-a-summary-index/m-p/80798#M807</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-05-29T20:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: stats dc behavior against a summary index</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/stats-dc-behavior-against-a-summary-index/m-p/80799#M808</link>
      <description>&lt;P&gt;sistats maintains the original values, placing those original values in a special field that stats then understands later. Try it. It works.&lt;/P&gt;

&lt;P&gt;The question is why won't stats perform a dc() on one of the "by" fields captured using sistats.&lt;/P&gt;

&lt;P&gt;This post from 2011 is an old approach. These days you'd use an accelerated data model, though if the sistats produced a sufficiently small number of rows, it might still be faster than the accelerated data model.&lt;/P&gt;</description>
      <pubDate>Sat, 30 May 2015 00:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/stats-dc-behavior-against-a-summary-index/m-p/80799#M808</guid>
      <dc:creator>vbumgarner</dc:creator>
      <dc:date>2015-05-30T00:32:11Z</dc:date>
    </item>
  </channel>
</rss>

