<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Get unique count by matching partial attributes in log in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Get-unique-count-by-matching-partial-attributes-in-log/m-p/84405#M21531</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I want to find out how many users have blue colors &amp;amp; how many of them have red color for all unique users?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[2011-09-30 18:15:01:559 GMT+00:00][137D3B5A5F196F81A405858E6A5AA01F.maps-358-thread-1][com.abc.myaction.myfilter] INFO email=abc@hotmail.com userid=1234
[2011-09-30 18:15:01:559 GMT+00:00][237D3B5A5F197F81A405858E6A5AA0WD.maps-158-thread1][com.abc.myaction.myfilter] INFO email=pqr@rff.com userid=4235
[2011-09-30 18:15:01:559 GMT+00:00][337D3B5A5F198F81A405858E6A5AA0GW.maps-258-thread-1][com.abc.myaction.myfilter] INFO email=xyz@abc.com userid=7645
[2011-09-30 18:14:58:768 GMT+00:00][237D3B5A5F198F81A405858E6A5AA09F.http-8080-11][com.pqr.abclogging.mywrapper] DEBUG redColor=true blueColor=false
[2011-09-30 18:14:58:768 GMT+00:00][237D3B5A5F197F81A405858E6A5AA0WD.http-8080-11][com.fff.filter] DEBUG redColor=true blueColor=false
[2011-09-30 18:14:58:768 GMT+00:00][137D3B5A5F196F81A405858E6A5AA01F.http-8080-11][com.xyz.wrapper] DEBUG redColor=false blueColor=true
[2011-09-30 18:14:58:768 GMT+00:00][337D3B5A5F198F81A405858E6A5AA0GW.http-8080-11][com.xyz.wrapper] DEBUG redColor=false blueColor=true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In above log, I've to get all distinct users &amp;amp; then for each user, I need to get their session id &amp;amp; them match it within the line that contains the DEBUG &amp;amp; check if redColor=true or not.&lt;/P&gt;

&lt;P&gt;So, in above case, the output should be:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;No of users with red color = 1 (Note: 237D3B5A5F198F81A405858E6A5AA09F does not match with anything, hence not counted even though its red flag is true)
No of users with blue color = 2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is this possible within splunk?&lt;/P&gt;</description>
    <pubDate>Fri, 30 Sep 2011 18:35:32 GMT</pubDate>
    <dc:creator>freephoneid</dc:creator>
    <dc:date>2011-09-30T18:35:32Z</dc:date>
    <item>
      <title>Get unique count by matching partial attributes in log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Get-unique-count-by-matching-partial-attributes-in-log/m-p/84405#M21531</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I want to find out how many users have blue colors &amp;amp; how many of them have red color for all unique users?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[2011-09-30 18:15:01:559 GMT+00:00][137D3B5A5F196F81A405858E6A5AA01F.maps-358-thread-1][com.abc.myaction.myfilter] INFO email=abc@hotmail.com userid=1234
[2011-09-30 18:15:01:559 GMT+00:00][237D3B5A5F197F81A405858E6A5AA0WD.maps-158-thread1][com.abc.myaction.myfilter] INFO email=pqr@rff.com userid=4235
[2011-09-30 18:15:01:559 GMT+00:00][337D3B5A5F198F81A405858E6A5AA0GW.maps-258-thread-1][com.abc.myaction.myfilter] INFO email=xyz@abc.com userid=7645
[2011-09-30 18:14:58:768 GMT+00:00][237D3B5A5F198F81A405858E6A5AA09F.http-8080-11][com.pqr.abclogging.mywrapper] DEBUG redColor=true blueColor=false
[2011-09-30 18:14:58:768 GMT+00:00][237D3B5A5F197F81A405858E6A5AA0WD.http-8080-11][com.fff.filter] DEBUG redColor=true blueColor=false
[2011-09-30 18:14:58:768 GMT+00:00][137D3B5A5F196F81A405858E6A5AA01F.http-8080-11][com.xyz.wrapper] DEBUG redColor=false blueColor=true
[2011-09-30 18:14:58:768 GMT+00:00][337D3B5A5F198F81A405858E6A5AA0GW.http-8080-11][com.xyz.wrapper] DEBUG redColor=false blueColor=true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In above log, I've to get all distinct users &amp;amp; then for each user, I need to get their session id &amp;amp; them match it within the line that contains the DEBUG &amp;amp; check if redColor=true or not.&lt;/P&gt;

&lt;P&gt;So, in above case, the output should be:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;No of users with red color = 1 (Note: 237D3B5A5F198F81A405858E6A5AA09F does not match with anything, hence not counted even though its red flag is true)
No of users with blue color = 2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is this possible within splunk?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2011 18:35:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Get-unique-count-by-matching-partial-attributes-in-log/m-p/84405#M21531</guid>
      <dc:creator>freephoneid</dc:creator>
      <dc:date>2011-09-30T18:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Get unique count by matching partial attributes in log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Get-unique-count-by-matching-partial-attributes-in-log/m-p/84406#M21532</link>
      <description>&lt;P&gt;Something like&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | stats count(eval(redColor=="true")) as redcount
            count(eval(blueColor=="true")) as bluecount
            first(userid) as userid by sessionid 
    | stats sum(redcount), sum(bluecount) by userid
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;would do it. &lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2011 23:29:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Get-unique-count-by-matching-partial-attributes-in-log/m-p/84406#M21532</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-09-30T23:29:26Z</dc:date>
    </item>
  </channel>
</rss>

