<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filter events using Distinct Count instead of dedup in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539508#M152576</link>
    <description>&lt;P&gt;When success=false, the dedup will pick up all the&amp;nbsp;&lt;SPAN&gt;customertripid which have failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When success=*, the dedup will pick up one of the status for the&amp;nbsp;customertripid so the failed count will be lower when there has been a success.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The results you have shown bear this out.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Feb 2021 15:33:31 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-02-11T15:33:31Z</dc:date>
    <item>
      <title>Filter events using Distinct Count instead of dedup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539504#M152575</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May I request you to help me with the query below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two fields "customertripid &amp;amp; success"&lt;/P&gt;&lt;P&gt;Customertripid has a unique id for a transaction - the transaction offers re-attempts on the same customertripid - so one transaction equal to one customertripid&lt;BR /&gt;&lt;BR /&gt;Problem :&lt;BR /&gt;Success=False&lt;BR /&gt;I want to capture all the events with unique customertripid where success=false (include those which passed eventually in reattempts) - I want to count them and use it to do %&lt;BR /&gt;&lt;BR /&gt;Success=Pass&lt;BR /&gt;That is giving correct counts...basically picking up the last attempt on each customertripid either 'passed' or 'failed'&lt;BR /&gt;&lt;BR /&gt;See the count here of fails when 'success=false' and when 'success=true'&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="beriwalnishant_4-1613056815101.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12901i0E2DC511C57B8228/image-size/medium?v=v2&amp;amp;px=400" role="button" title="beriwalnishant_4-1613056815101.png" alt="beriwalnishant_4-1613056815101.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Nishant&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 15:22:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539504#M152575</guid>
      <dc:creator>beriwalnishant</dc:creator>
      <dc:date>2021-02-11T15:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Filter events using Distinct Count instead of dedup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539508#M152576</link>
      <description>&lt;P&gt;When success=false, the dedup will pick up all the&amp;nbsp;&lt;SPAN&gt;customertripid which have failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When success=*, the dedup will pick up one of the status for the&amp;nbsp;customertripid so the failed count will be lower when there has been a success.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The results you have shown bear this out.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 15:33:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539508#M152576</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-02-11T15:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: Filter events using Distinct Count instead of dedup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539509#M152577</link>
      <description>&lt;P&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Sorry, does that mean there is no way out to this&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 15:39:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539509#M152577</guid>
      <dc:creator>beriwalnishant</dc:creator>
      <dc:date>2021-02-11T15:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Filter events using Distinct Count instead of dedup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539513#M152579</link>
      <description>&lt;P&gt;Rather dedup try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats count by customertripid success
| stats count by success&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 11 Feb 2021 16:13:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539513#M152579</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-02-11T16:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Filter events using Distinct Count instead of dedup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539610#M152607</link>
      <description>&lt;P&gt;I am afraid but this didn't work.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 03:48:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539610#M152607</guid>
      <dc:creator>beriwalnishant</dc:creator>
      <dc:date>2021-02-12T03:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Filter events using Distinct Count instead of dedup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539662#M152633</link>
      <description>&lt;P&gt;In what way does this not work?&lt;/P&gt;&lt;P&gt;The first stats gives you a count of event for each combination of&amp;nbsp;customertripid and success&lt;/P&gt;&lt;P&gt;The second stats gives you the number of unique customertripid for each type of success - is this not what you wanted?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 10:34:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539662#M152633</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-02-12T10:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Filter events using Distinct Count instead of dedup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539679#M152637</link>
      <description>&lt;P&gt;My bad on not adding more details - I mean by standalone it works however I want to do this...&lt;/P&gt;&lt;P&gt;how can I use this to do this .... using your solution (this dedup doesnt count a txn that followed series of fail attempts before getting passed bearing same customertripid (see explanation below)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="beriwalnishant_0-1613132981952.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12919i0AF7DA0103ED1485/image-size/medium?v=v2&amp;amp;px=400" role="button" title="beriwalnishant_0-1613132981952.png" alt="beriwalnishant_0-1613132981952.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried using your method below but no results returned&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="beriwalnishant_1-1613132998258.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12920i2F60D104618AF94C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="beriwalnishant_1-1613132998258.png" alt="beriwalnishant_1-1613132998258.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="beriwalnishant_2-1613133001956.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12921iDC6BED8654F0AEF6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="beriwalnishant_2-1613133001956.png" alt="beriwalnishant_2-1613133001956.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's where the struggle is - if I can do this I basically would be able to count each transaction on its last status....each transaction bears a customertripid.....and each transaction gets reattempted....all the following re-attempts bears the same customertripid&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The end result could be that the transaction after a number of attempts (3 or 4 or 5 depending upon the front user) stops at as 'fail' or stops at 'pass'&lt;BR /&gt;&lt;BR /&gt;Irrespective of it being passed I want to pick the last 'fail' to get the count of those fails also which passed so that we know that if a transaction was 'passed' did it follow any re-attempts due to being failed or just a pass&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again and sorry for saying your solution didnt work....I mean I didnt add all the details to tell you how your solution to make work the way I want&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Nishant&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 12:34:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539679#M152637</guid>
      <dc:creator>beriwalnishant</dc:creator>
      <dc:date>2021-02-12T12:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Filter events using Distinct Count instead of dedup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539684#M152638</link>
      <description>&lt;P&gt;The reason you get no results is that the stats command returns two fields customertripid and success so the chart command does not have a field tpid to work with. Either customertripid should be tpid or vice versa depending on the fields returned by the search.&lt;/P&gt;&lt;P&gt;Having said that, I am not sure why you are not doing&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats count(eval(success="false")) as Total_Failed count(eval(success="true")) as Total_Passed count as Total by customertripid
| eval Failed_Ratio=(round((Total_Failed/Total)*100,2)
| where Failed_Ratio &amp;gt; 0
| fields customertripid, Failed_Ratio, Total&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Main issue with this is if a passed transaction is reattempted and passes or fails again as this skews the results (slightly). Also, do you need to know if any the transaction passed? If so, you could keep the Total_Passed field as well&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 13:13:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539684#M152638</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-02-12T13:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Filter events using Distinct Count instead of dedup</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539785#M152678</link>
      <description>&lt;P&gt;Ohh you have no idea that you really solved it the way I wanted. I continued to add the fields in first stats as&lt;/P&gt;&lt;P&gt;| stats count by customertripid, success, tpid, morefield, morefield&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Than keep your stats eval count separate like normal. What all field you want continue to add it.&amp;nbsp;&lt;BR /&gt;you have given such a simple solution to a complex problem that I couldn’t find anywhere, even in my office’s splunk support team.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;hats off to you. thanks a lot to you.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Nishant&lt;/P&gt;</description>
      <pubDate>Sat, 13 Feb 2021 11:02:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-events-using-Distinct-Count-instead-of-dedup/m-p/539785#M152678</guid>
      <dc:creator>beriwalnishant</dc:creator>
      <dc:date>2021-02-13T11:02:14Z</dc:date>
    </item>
  </channel>
</rss>

