<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Distinct Count of Field1 and field2 in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Distinct-Count-of-Field1-and-field2/m-p/527676#M148969</link>
    <description>&lt;LI-CODE lang="markup"&gt;| eval trackingid=coalesce(trackingid,trackingId)&lt;/LI-CODE&gt;</description>
    <pubDate>Tue, 03 Nov 2020 09:29:11 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2020-11-03T09:29:11Z</dc:date>
    <item>
      <title>Distinct Count of Field1 and field2</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Distinct-Count-of-Field1-and-field2/m-p/527610#M148949</link>
      <description>&lt;P&gt;I am trying to get a distinct count of tacking id from all of our production indexes. The issue I am running into is that for internal indexes my field of interest is named "trackingid" and for external indexes the field is named "trackingId".&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried several things and can only get values for either internal or external, and or both in separate columns. I cannot get both fields renamed as "tid". Which would then be split by region based on host.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 23:20:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Distinct-Count-of-Field1-and-field2/m-p/527610#M148949</guid>
      <dc:creator>heamik</dc:creator>
      <dc:date>2020-11-02T23:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: Distinct Count of Field1 and field2</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Distinct-Count-of-Field1-and-field2/m-p/527676#M148969</link>
      <description>&lt;LI-CODE lang="markup"&gt;| eval trackingid=coalesce(trackingid,trackingId)&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 03 Nov 2020 09:29:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Distinct-Count-of-Field1-and-field2/m-p/527676#M148969</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-11-03T09:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Distinct Count of Field1 and field2</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Distinct-Count-of-Field1-and-field2/m-p/527746#M148990</link>
      <description>&lt;P&gt;Thank you so much!!! That solved the problem perfectly!&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 14:50:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Distinct-Count-of-Field1-and-field2/m-p/527746#M148990</guid>
      <dc:creator>heamik</dc:creator>
      <dc:date>2020-11-03T14:50:42Z</dc:date>
    </item>
  </channel>
</rss>

