<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic streamstats | reset_after condition not applied within the scope of each user (field) in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/streamstats-reset-after-condition-not-applied-within-the-scope/m-p/692013#M235578</link>
    <description>&lt;P&gt;Hi Team,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;What I'm trying to achieve: Find the consecutive failure events followed by a success event.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;| makeresults | eval _raw="username,result
user1,fail
user2,success
user3,success
user1,fail
user1,fail
user1,success
user2,fail
user3,success
user2,fail
user1,fail"
| multikv forceheader=1
| streamstats count(eval(result="fail")) as fail_counter by username,result reset_after="("result==\"success\"")"
| table  username,result,fail_counter&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Outcome: The counter (fail_counter) gets reset for a user (say user1) if the next event is a success event for a different user (say, user2).&lt;/P&gt;&lt;TABLE border="1" width="46.968544656100676%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD height="25px"&gt;username&lt;/TD&gt;&lt;TD height="25px"&gt;result&lt;/TD&gt;&lt;TD height="25px"&gt;fail_counter&lt;/TD&gt;&lt;TD height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user1&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;fail&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user2&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;success&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;0&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user3&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;success&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;0&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="135px"&gt;&lt;FONT color="#FF6600"&gt;user1&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="135px"&gt;&lt;FONT color="#FF6600"&gt;fail&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="135px"&gt;&lt;FONT color="#FF6600"&gt;1&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="135px"&gt;&lt;FONT color="#FF6600"&gt;&amp;lt;- counter reset for user1. It should be 2.&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;user1&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="47px"&gt;fail&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="47px"&gt;2&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;It should be 3.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user1&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;success&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;0&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user2&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;fail&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user3&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;success&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;0&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&lt;FONT color="#FF6600"&gt;user2&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;&lt;FONT color="#FF6600"&gt;fail&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;&lt;FONT color="#FF6600"&gt;1&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user1&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;fail&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;Expected: The counter should not reset if the success event for user2 follows the failure event for user1.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I would appreciate any help on this. Not sure what I'm missing here.&lt;/P&gt;</description>
    <pubDate>Sun, 30 Jun 2024 15:29:58 GMT</pubDate>
    <dc:creator>ralam</dc:creator>
    <dc:date>2024-06-30T15:29:58Z</dc:date>
    <item>
      <title>streamstats | reset_after condition not applied within the scope of each user (field)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/streamstats-reset-after-condition-not-applied-within-the-scope/m-p/692013#M235578</link>
      <description>&lt;P&gt;Hi Team,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;What I'm trying to achieve: Find the consecutive failure events followed by a success event.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;| makeresults | eval _raw="username,result
user1,fail
user2,success
user3,success
user1,fail
user1,fail
user1,success
user2,fail
user3,success
user2,fail
user1,fail"
| multikv forceheader=1
| streamstats count(eval(result="fail")) as fail_counter by username,result reset_after="("result==\"success\"")"
| table  username,result,fail_counter&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Outcome: The counter (fail_counter) gets reset for a user (say user1) if the next event is a success event for a different user (say, user2).&lt;/P&gt;&lt;TABLE border="1" width="46.968544656100676%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD height="25px"&gt;username&lt;/TD&gt;&lt;TD height="25px"&gt;result&lt;/TD&gt;&lt;TD height="25px"&gt;fail_counter&lt;/TD&gt;&lt;TD height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user1&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;fail&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user2&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;success&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;0&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user3&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;success&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;0&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="135px"&gt;&lt;FONT color="#FF6600"&gt;user1&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="135px"&gt;&lt;FONT color="#FF6600"&gt;fail&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="135px"&gt;&lt;FONT color="#FF6600"&gt;1&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="135px"&gt;&lt;FONT color="#FF6600"&gt;&amp;lt;- counter reset for user1. It should be 2.&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;user1&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="47px"&gt;fail&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="47px"&gt;2&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="47px"&gt;It should be 3.&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user1&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;success&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;0&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user2&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;fail&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user3&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;success&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;0&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&lt;FONT color="#FF6600"&gt;user2&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;&lt;FONT color="#FF6600"&gt;fail&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;&lt;FONT color="#FF6600"&gt;1&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;user1&lt;/TD&gt;&lt;TD width="14.267676767676768%" height="25px"&gt;fail&lt;/TD&gt;&lt;TD width="15.656565656565657%" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;Expected: The counter should not reset if the success event for user2 follows the failure event for user1.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I would appreciate any help on this. Not sure what I'm missing here.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2024 15:29:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/streamstats-reset-after-condition-not-applied-within-the-scope/m-p/692013#M235578</guid>
      <dc:creator>ralam</dc:creator>
      <dc:date>2024-06-30T15:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: streamstats | reset_after condition not applied within the scope of each user (field)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/streamstats-reset-after-condition-not-applied-within-the-scope/m-p/692015#M235580</link>
      <description>&lt;P&gt;You could try sorting by username before the streamstats&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2024 15:50:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/streamstats-reset-after-condition-not-applied-within-the-scope/m-p/692015#M235580</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-06-30T15:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: streamstats | reset_after condition not applied within the scope of each user (field)</title>
      <link>https://community.splunk.com/t5/Splunk-Search/streamstats-reset-after-condition-not-applied-within-the-scope/m-p/692028#M235585</link>
      <description>&lt;P&gt;The docs on the streamstats command say that "all accumulated statistics" are reset on reset_* options. That would imply that the reset is global, not on a per "by-field(s)" basis.&lt;/P&gt;&lt;P&gt;It could call for docs feedback to make it more explicitly stated.&lt;/P&gt;&lt;P&gt;The practical solution to this you already got from &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2024 18:36:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/streamstats-reset-after-condition-not-applied-within-the-scope/m-p/692028#M235585</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-06-30T18:36:54Z</dc:date>
    </item>
  </channel>
</rss>

