<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unique user/unique client in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/740983#M58344</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/158935"&gt;@yeahnah&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I want to display in the similar tabular way what showed but not giving&amp;nbsp; on specific json as taking as makeresult...&lt;BR /&gt;I have the event flowing in&amp;nbsp; two format which i shared earlier in the splunk.can you help on this&lt;/P&gt;</description>
    <pubDate>Thu, 06 Mar 2025 00:35:22 GMT</pubDate>
    <dc:creator>nithys</dc:creator>
    <dc:date>2025-03-06T00:35:22Z</dc:date>
    <item>
      <title>unique user/unique client</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/740666#M58324</link>
      <description>&lt;P class=""&gt;Hi&amp;nbsp;&lt;BR /&gt;Need to find&amp;nbsp;&lt;STRONG&gt;Unique Users(Count of distinct business users )&amp;amp; Clients(Count of distinct system client accounts )&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;I want to&amp;nbsp; have&amp;nbsp;&lt;STRONG&gt;Unique Users and unqiue client based on cid.id and its associated groups&lt;BR /&gt;&lt;BR /&gt;example&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="20%"&gt;app&lt;/TD&gt;&lt;TD width="20%"&gt;unique user&lt;/TD&gt;&lt;TD width="20%"&gt;unique client&lt;/TD&gt;&lt;TD width="20%"&gt;groups&lt;/TD&gt;&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%"&gt;name.id&lt;/TD&gt;&lt;TD width="20%"&gt;22&lt;/TD&gt;&lt;TD width="20%"&gt;1&lt;/TD&gt;&lt;TD width="20%"&gt;app.preprod.name&lt;/TD&gt;&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%"&gt;address.id&lt;/TD&gt;&lt;TD width="20%"&gt;1&lt;/TD&gt;&lt;TD width="20%"&gt;1&lt;/TD&gt;&lt;TD width="20%"&gt;app.preprod.address,app.preprod.zipcode&lt;/TD&gt;&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P class=""&gt;&lt;BR /&gt;&lt;BR /&gt;index= AND source="*"&lt;BR /&gt;| stats dc( claims.sub) as "Unique Users" ``` dc(claims.sub) as "Unique Users" count(claims.sub) as "Total" ```&lt;BR /&gt;```| addcoltotals labelfield="Grand Total"`&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{"name":"","hostname":"1","pid":8,"level":,"claims":{"ver":1,"jti":"h7","iss":"https","aud":"https://p","iat":1,"exp":17,"cid":"name.id","uid":"00","scp":["update:","offline_access","read:","readall:","create:","openid","delete:","execute:","read:"],"auth_time":17,"sub":"name@gmail.com","groups":["App.PreProd.name"]},"msg":" JWT Claims -API","time":"2025","v":0}&lt;/LI-CODE&gt;&lt;P class=""&gt;unique client&lt;BR /&gt;&lt;BR /&gt;index=* AND source="*"&lt;BR /&gt;| stats dc( claims.cid) as "Unique Clients" ``` dc(claims.sub) as "Unique Users" count(claims.sub) as "Total" ```&lt;BR /&gt;```| addcoltotals labelfield="Grand Total"```&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;"name":"","hostname":"1","pid":8,"level":,"claims":{"ver":1,"jti":"h7","iss":"https","aud":"https://p","iat":1,"exp":17,"cid":"address.id","uid":"00","scp":["update:","offline_access","read:","readall:","create:","openid","delete:","execute:","read:"],"auth_time":17,"sub":"name@gmail.com","groups":["App.PreProd.address,app.preprod.zipcode"]},"msg":" JWT Claims -API","time":"2025","v":0}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 00:45:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/740666#M58324</guid>
      <dc:creator>nithys</dc:creator>
      <dc:date>2025-03-04T00:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: unique user/unique client</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/740667#M58325</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260549"&gt;@nithys&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Something like this should work ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=dummy
| append [ | makeresults count=22
| eval json=split("{\"name\":\"\",\"hostname\":\"1\",\"pid\":8,\"level\":\"\",\"claims\":{\"ver\":1,\"jti\":\"h7\",\"iss\":\"https\",\"aud\":\"https://p\",\"iat\":1,\"exp\":17,\"cid\":\"name.id\",\"uid\":\"00\",\"scp\":[\"update:\",\"offline_access\",\"read:\",\"readall:\",\"create:\",\"openid\",\"delete:\",\"execute:\",\"read:\"],\"auth_time\":17,\"sub\":\"name@gmail.com\",\"groups\":[\"App.PreProd.name\"]},\"msg\":\" JWT Claims -API\",\"time\":\"2025\",\"v\":0} | {\"name\":\"\",\"hostname\":\"1\",\"pid\":8,\"level\":\"\",\"claims\":{\"ver\":1,\"jti\":\"h7\",\"iss\":\"https\",\"aud\":\"https://p\",\"iat\":1,\"exp\":17,\"cid\":\"address.id\",\"uid\":\"00\",\"scp\":[\"update:\",\"offline_access\",\"read:\",\"readall:\",\"create:\",\"openid\",\"delete:\",\"execute:\",\"read:\"],\"auth_time\":17,\"sub\":\"name@gmail.com\",\"groups\":[\"App.PreProd.address,app.preprod.zipcode\"]},\"msg\":\" JWT Claims -API\",\"time\":\"2025\",\"v\":0}", " | ")
]
| mvexpand json
| eval _raw=json
| spath
| streamstats count
| eval "claims.sub"=if(count%2=0, count."_".'claims.sub', 'claims.sub')
 ``` ^^^ create dummy events ^^^ ```
| stats dc(claims.sub) as "Unique Users"
        dc(claims.cid) as "Unique Clients"
  BY claims.cid claims.groups{}
| rename claims.cid AS app claims.groups{} AS groups
| table app "Unique Users" "Unique Clients" groups&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 01:57:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/740667#M58325</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2025-03-04T01:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: unique user/unique client</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/740684#M58327</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260549"&gt;@nithys&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;when you use json fields use brachets or rename them:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index= AND source="*"
| rename claims.sub AS claims_sub
| stats dc(claims_sub) as "Unique Users" ``` dc(claims.sub) as "Unique Users" count(claims_sub) as "Total" ```
```| addcoltotals labelfield="Grand Total"`&lt;/LI-CODE&gt;&lt;P&gt;or&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index= AND source="*"
| stats dc('claims.sub') as "Unique Users" ``` dc(claims.sub) as "Unique Users" count(claims.sub) as "Total" ```
```| addcoltotals labelfield="Grand Total"`&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 07:44:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/740684#M58327</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-03-04T07:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: unique user/unique client</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/740770#M58335</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/158935"&gt;@yeahnah&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I used in below way where unique user count is not matching ,why i need to provide specify json...I want to fetch from all event from the splunk log give the unique user list for their specify group .group can respresent in [group 1,group 2] or [group1]...then fetch&amp;nbsp;&lt;BR /&gt;unique user list of&amp;nbsp;[App.Au1,App.Au2] in one row and&amp;nbsp;unique user list of&amp;nbsp;[App.Au1] in second row&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-03-04 at 6.10.09 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/37982i2130A51EA95F772F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-03-04 at 6.10.09 AM.png" alt="Screenshot 2025-03-04 at 6.10.09 AM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-03-04 at 6.04.06 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/37983i6998DBF17799293B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-03-04 at 6.04.06 AM.png" alt="Screenshot 2025-03-04 at 6.04.06 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 14:17:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/740770#M58335</guid>
      <dc:creator>nithys</dc:creator>
      <dc:date>2025-03-04T14:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: unique user/unique client</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/740983#M58344</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/158935"&gt;@yeahnah&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I want to display in the similar tabular way what showed but not giving&amp;nbsp; on specific json as taking as makeresult...&lt;BR /&gt;I have the event flowing in&amp;nbsp; two format which i shared earlier in the splunk.can you help on this&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 00:35:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/740983#M58344</guid>
      <dc:creator>nithys</dc:creator>
      <dc:date>2025-03-06T00:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: unique user/unique client</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/741240#M58363</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260549"&gt;@nithys&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Mar 2025 15:59:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/unique-user-unique-client/m-p/741240#M58363</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-03-09T15:59:44Z</dc:date>
    </item>
  </channel>
</rss>

