<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic dedup within timechart in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86389#M22026</link>
    <description>&lt;P&gt;I have several searches that I am trying to optimize now that our platform is on splunk 5+.  My preference is to leverage report acceleration because of its ability to dynamically back-fill the way it efficiently runs in the background.&lt;/P&gt;

&lt;P&gt;Unfortunately, several of my searches use a dedup on multiple fields (ie: dedup field1 field2 field3) and then runs timechart against one of those fields (ie: timechart span=1d field1).  The use of dedup before timechart prevents report acceleration from being used as its not a streamable command.&lt;/P&gt;

&lt;P&gt;I'm trying to find a way to eliminate to enable this search for report acceleration.&lt;/P&gt;

&lt;P&gt;I've tried removing the dedup and playing with distinctcount(field1 field2 field3) but that failed. I also tried timechart span=1d dc(field1) by field2 field3 but that also is not allowed.  I'm suspicious that I'm overlooking a trivial way to do this. Perhaps the community can enlighten me?&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2013 19:10:14 GMT</pubDate>
    <dc:creator>sloshburch</dc:creator>
    <dc:date>2013-07-05T19:10:14Z</dc:date>
    <item>
      <title>dedup within timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86389#M22026</link>
      <description>&lt;P&gt;I have several searches that I am trying to optimize now that our platform is on splunk 5+.  My preference is to leverage report acceleration because of its ability to dynamically back-fill the way it efficiently runs in the background.&lt;/P&gt;

&lt;P&gt;Unfortunately, several of my searches use a dedup on multiple fields (ie: dedup field1 field2 field3) and then runs timechart against one of those fields (ie: timechart span=1d field1).  The use of dedup before timechart prevents report acceleration from being used as its not a streamable command.&lt;/P&gt;

&lt;P&gt;I'm trying to find a way to eliminate to enable this search for report acceleration.&lt;/P&gt;

&lt;P&gt;I've tried removing the dedup and playing with distinctcount(field1 field2 field3) but that failed. I also tried timechart span=1d dc(field1) by field2 field3 but that also is not allowed.  I'm suspicious that I'm overlooking a trivial way to do this. Perhaps the community can enlighten me?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2013 19:10:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86389#M22026</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2013-07-05T19:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: dedup within timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86390#M22027</link>
      <description>&lt;P&gt;Post your search and what you want to achieve with it - maybe there is an entirely different approach.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2013 19:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86390#M22027</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-07-05T19:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: dedup within timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86391#M22028</link>
      <description>&lt;P&gt;Fair request.  I tried to abstract the company stuff so hopefully this still is clear for the community:&lt;/P&gt;

&lt;P&gt;index=a ( sourcetype="b" OR sourcetype="c" ) ( source="/path/file1*" OR source="/path/file2*" ) fieldA=* ( fieldB=val1 OR fieldC=val2 )&lt;BR /&gt;
 | convert timeformat="%m/%d/%y" ctime(_time) as Date1 &lt;BR /&gt;
 | timechart span=1day dc(eval(fieldD.";".fieldE.";".Date1)) as countFieldName &lt;BR /&gt;
 | convert timeformat="%m/%d/%y" ctime(_time) as Date &lt;BR /&gt;
 | table Date countFieldName&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:16:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86391#M22028</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2020-09-28T14:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: dedup within timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86392#M22029</link>
      <description>&lt;P&gt;Notice the use of dc(eval(fieldD.";".fieldE.";".Date1)).  My thought was to create a unique string from the fields I would dedup against, then get a distinct count of those.  Again, I assume I'm hacking this and there's probably a more trivial approach I should be using.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2013 19:41:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86392#M22029</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2013-07-05T19:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: dedup within timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86393#M22030</link>
      <description>&lt;P&gt;And what are you trying to achieve here, in natural language rather than SPL?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2013 23:04:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86393#M22030</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-07-05T23:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: dedup within timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86394#M22031</link>
      <description>&lt;P&gt;The goal is to enable report acceleration on a pre-existing saved search - but the saved search was designed with dedup  on several fields before the timechart command.  So the folks that use the saved search want to timechart some distinct values.  Is that more clear? Thanks for the clarifying questions.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2013 12:40:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86394#M22031</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2013-07-08T12:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: dedup within timechart</title>
      <link>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86395#M22032</link>
      <description>&lt;P&gt;I believe I found a solution: do a stats count by field1 field2 field3 where field3 is the timepan (in this case, just the day of the _time).  If I'm thinking clearly, that will dedup by those three fields.  Then, if I want a total count, I can do another stats count.  This results in a distinct count.  I believe this should be more efficient than the eval approach.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2013 15:07:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/dedup-within-timechart/m-p/86395#M22032</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2013-07-17T15:07:03Z</dc:date>
    </item>
  </channel>
</rss>

