<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need Help Creating a Nested Stats Table and Grouping by Multiple Values in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-Creating-a-Nested-Stats-Table-and-Grouping-by-Multiple/m-p/569136#M198358</link>
    <description>&lt;P&gt;Figured it out, pretty simple but I was doing the operations in the wrong order originally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="my_custom_index" "properties.requestUri"="http*://my.customwebpage.com:443/api/NotARealEndpoint/*/CoolCars/*" AND NOT "properties.clientIp"="127.0.*.*" AND NOT properties.httpStatusCode=401 |rex field="properties.requestUri" "http(.):\/\/my.customwebpage.com:(\d+)\/api\/NotARealEndpoint\/(?&amp;lt;uniqueHash&amp;gt;[a-zA-z0-9].+[^\/])\/CoolCars\/(?&amp;lt;CarID&amp;gt;[\d].+)"
| stats count by properties.clientIp, uniqueHash, CarID
| stats list(uniqueHash) as UniqueHash, list(CarID) as CarID, list(count) as Count by properties.clientIp
| append [
search index="my_custom_index" "properties.requestUri"="http*://my.customwebpage.com:443/api/NotARealEndpoint/*/CoolCars/*" AND NOT "properties.clientIp"="127.0.*.*" |rex field="properties.requestUri" "http(.):\/\/my.customwebpage.com:(\d+)\/api\/NotARealEndpoint\/(?&amp;lt;uniqueHash&amp;gt;[a-zA-z0-9].+[^\/])\/CoolCars\/(?&amp;lt;CarID&amp;gt;[\d].+)"
| stats count by uniqueHash,CarID
] | table properties.clientIp, UniqueHash, CarID, Count&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Sep 2021 12:59:26 GMT</pubDate>
    <dc:creator>TheColorBlack</dc:creator>
    <dc:date>2021-09-30T12:59:26Z</dc:date>
    <item>
      <title>Need Help Creating a Nested Stats Table and Grouping by Multiple Values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-Creating-a-Nested-Stats-Table-and-Grouping-by-Multiple/m-p/568986#M198313</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need some quick help creating a nested stats table and grouping by multiple values within that table. My data contains the following data points that I am trying to correlate / visualize: Client IP Address, Unique Hash ID, Unique Document ID, and the count that shows the number of times an IP Address accessed a Unique Hash ID, and Doc ID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An example data set is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;192.168.1.1 (client IP), abcdefg1 (hash 1),&amp;nbsp; 12948(DocID1), 129584(DocID2), 1029384(DocID3)&lt;/P&gt;&lt;P&gt;192.168.1.1(Client IP), abcdefg2 (hash 2), 10294 (DocID 1),&lt;/P&gt;&lt;P&gt;192.168.1.5(Client IP), abcdefg1 (hash1), 12948(DocID1), 1029484(DocID2)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking to create the following table to help visualize these relationships&lt;BR /&gt;&lt;BR /&gt;|&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="16.666666666666668%"&gt;Client IP&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;Unique Hash&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;Document ID&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;Count&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="16.666666666666668%"&gt;192.168.1.1&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;abcdefg1&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;12948&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;5&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;129584&lt;/TD&gt;&lt;TD&gt;10&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;1029384&lt;/TD&gt;&lt;TD&gt;15&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;abcdefg2&lt;/TD&gt;&lt;TD&gt;12948&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;1029484&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;3&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="16.666666666666668%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;192.168.1.5&lt;/TD&gt;&lt;TD&gt;abcdefg1&lt;/TD&gt;&lt;TD&gt;12948&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;1029484&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've created nested tables before but I'm really stumping myself on this one. Any advice?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 18:18:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-Creating-a-Nested-Stats-Table-and-Grouping-by-Multiple/m-p/568986#M198313</guid>
      <dc:creator>TheColorBlack</dc:creator>
      <dc:date>2021-09-29T18:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help Creating a Nested Stats Table and Grouping by Multiple Values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-Creating-a-Nested-Stats-Table-and-Grouping-by-Multiple/m-p/569136#M198358</link>
      <description>&lt;P&gt;Figured it out, pretty simple but I was doing the operations in the wrong order originally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="my_custom_index" "properties.requestUri"="http*://my.customwebpage.com:443/api/NotARealEndpoint/*/CoolCars/*" AND NOT "properties.clientIp"="127.0.*.*" AND NOT properties.httpStatusCode=401 |rex field="properties.requestUri" "http(.):\/\/my.customwebpage.com:(\d+)\/api\/NotARealEndpoint\/(?&amp;lt;uniqueHash&amp;gt;[a-zA-z0-9].+[^\/])\/CoolCars\/(?&amp;lt;CarID&amp;gt;[\d].+)"
| stats count by properties.clientIp, uniqueHash, CarID
| stats list(uniqueHash) as UniqueHash, list(CarID) as CarID, list(count) as Count by properties.clientIp
| append [
search index="my_custom_index" "properties.requestUri"="http*://my.customwebpage.com:443/api/NotARealEndpoint/*/CoolCars/*" AND NOT "properties.clientIp"="127.0.*.*" |rex field="properties.requestUri" "http(.):\/\/my.customwebpage.com:(\d+)\/api\/NotARealEndpoint\/(?&amp;lt;uniqueHash&amp;gt;[a-zA-z0-9].+[^\/])\/CoolCars\/(?&amp;lt;CarID&amp;gt;[\d].+)"
| stats count by uniqueHash,CarID
] | table properties.clientIp, UniqueHash, CarID, Count&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 12:59:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-Creating-a-Nested-Stats-Table-and-Grouping-by-Multiple/m-p/569136#M198358</guid>
      <dc:creator>TheColorBlack</dc:creator>
      <dc:date>2021-09-30T12:59:26Z</dc:date>
    </item>
  </channel>
</rss>

