<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tstats, no using stats-function-field, using row-field. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/554216#M157330</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229779"&gt;@nasha430&lt;/a&gt;&amp;nbsp; Great!&lt;/P&gt;</description>
    <pubDate>Thu, 03 Jun 2021 07:50:06 GMT</pubDate>
    <dc:creator>aasabatini</dc:creator>
    <dc:date>2021-06-03T07:50:06Z</dc:date>
    <item>
      <title>tstats, no using stats-function-field, using row-field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553467#M157144</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use tstats, but tstats use required argument ( stats-func ).&lt;BR /&gt;I want to write SPL.&lt;/P&gt;&lt;P&gt;| tstats summariesonly=t &amp;lt;field1&amp;gt;, &amp;lt;field2&amp;gt; FROM datamodel=&amp;lt;datamodel-name&amp;gt; BY &amp;lt;field3&amp;gt;&lt;/P&gt;&lt;P&gt;| dedup &amp;lt;field1&amp;gt;&amp;nbsp;&lt;BR /&gt;| stats sum(&amp;lt;field2&amp;gt;) by &amp;lt;fields1&amp;gt;&lt;BR /&gt;&lt;BR /&gt;Is this possible??&amp;nbsp;&lt;/P&gt;&lt;P&gt;datamodel acceleration is done.&lt;BR /&gt;I'm looking for manual for this,but I don't detect manual about tstats.&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 09:07:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553467#M157144</guid>
      <dc:creator>nasha430</dc:creator>
      <dc:date>2021-05-28T09:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: tstats, no using stats-function-field, using row-field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553474#M157147</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229779"&gt;@nasha430&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;absolutely yes!&lt;/P&gt;&lt;P&gt;below you can find my example, I used authentication datamodel&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope can help&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats `summariesonly` values(Authentication.app) as app,values(Authentication.user) as user, 
count from datamodel=Authentication.Authentication where Authentication.action="failure"  by Authentication.action,Authentication.src 
| dedup user
| stats sum(user) by app&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 May 2021 09:53:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553474#M157147</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-28T09:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: tstats, no using stats-function-field, using row-field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553672#M157206</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222210"&gt;@aasabatini&lt;/a&gt;&amp;nbsp;Thanks you, your message.&lt;/P&gt;&lt;P&gt;but I want to see field, not stats field.&lt;BR /&gt;Based on your SPL, I want to see this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats `summariesonly` Authentication.app as app,Authentication.user as user, 
count from datamodel=Authentication.Authentication where Authentication.action="failure"  by Authentication.action,Authentication.src 
| dedup user
| stats sum(app) by user&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;because I need deduplication of user event and I don't need&amp;nbsp; deduplication of&amp;nbsp;app data.&lt;/P&gt;</description>
      <pubDate>Sun, 30 May 2021 23:57:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553672#M157206</guid>
      <dc:creator>nasha430</dc:creator>
      <dc:date>2021-05-30T23:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: tstats, no using stats-function-field, using row-field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553691#M157212</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229779"&gt;@nasha430&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't understand your request, with the Tstats function is not possible create a search with a normal SPL, you must use stats function like values or sum, maybe you can use datamodel command but is not accelerated.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Alessandro&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 07:42:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553691#M157212</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-31T07:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: tstats, no using stats-function-field, using row-field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553745#M157225</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222210"&gt;@aasabatini&lt;/a&gt;&amp;nbsp;Hello!&lt;BR /&gt;Please, let you know my conditional factor. Exactly not use tstats command. ( I still am solving my situation, I study lookup command. I will finish my situation with hope.)&lt;/P&gt;&lt;P&gt;fields : user(data: STRING), reg_no(data:NUMBER), FILE_HASH(data : HASHCODE)&lt;/P&gt;&lt;P&gt;1. I use 'datamodel acceleration'.&lt;BR /&gt;2. I do 'FILE_HASH(field) deduplication'. Event have deduplicated.&lt;/P&gt;&lt;P&gt;3. After deduplication, I use sum(reg_no).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;So I try code.&lt;BR /&gt;| tstats summariesonly=t reg_no FILE_HASH FROM datamodel="&amp;lt;datamodel&amp;gt;" by user&lt;/P&gt;&lt;P&gt;| dedup FILE_HASH&lt;/P&gt;&lt;P&gt;| stats sum(reg_no) by user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But tstats don't use fields... so I have to find other way.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I will try lookup command! Maybe let me know other thinking or command.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 01:07:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553745#M157225</guid>
      <dc:creator>nasha430</dc:creator>
      <dc:date>2021-06-01T01:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: tstats, no using stats-function-field, using row-field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553749#M157228</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222210"&gt;@aasabatini&lt;/a&gt;&amp;nbsp;Hi!&lt;/P&gt;&lt;P&gt;In my thought If tstats use 'list' command, my issue can be solved.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see search reference, can't use 'list' function.&lt;BR /&gt;Can it be Other way?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 01:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553749#M157228</guid>
      <dc:creator>nasha430</dc:creator>
      <dc:date>2021-06-01T01:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: tstats, no using stats-function-field, using row-field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553755#M157229</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222210"&gt;@aasabatini&lt;/a&gt;&amp;nbsp; Oh! I find solution!!&lt;/P&gt;&lt;P&gt;Thanks... because you listen my issue, I find my solution. ㅠㅠ.&lt;/P&gt;&lt;P&gt;This is my way.&lt;/P&gt;&lt;P&gt;| tstats summariesonly=t values(&amp;lt;dataset&amp;gt;.reg_no) as reg_no FROM datamodel=&amp;lt;datamodel&amp;gt; BY &amp;lt;dataset&amp;gt;.user &amp;lt;dataset&amp;gt;.FILE_HASH&lt;BR /&gt;| dedup &amp;lt;dataset&amp;gt;.user &amp;lt;dataset&amp;gt;.FILE_HASH&lt;BR /&gt;| stats sum(reg_no) by &amp;lt;dataset&amp;gt;.user&lt;BR /&gt;&lt;BR /&gt;Thanks aasabatini!! good luck.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 02:32:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/553755#M157229</guid>
      <dc:creator>nasha430</dc:creator>
      <dc:date>2021-06-01T02:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: tstats, no using stats-function-field, using row-field.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/554216#M157330</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229779"&gt;@nasha430&lt;/a&gt;&amp;nbsp; Great!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 07:50:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/tstats-no-using-stats-function-field-using-row-field/m-p/554216#M157330</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-06-03T07:50:06Z</dc:date>
    </item>
  </channel>
</rss>

