<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: conditional distinct count in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/conditional-distinct-count/m-p/185823#M53548</link>
    <description>&lt;P&gt;index = webs process_resource&amp;gt;=0 subs_id&amp;gt;0 | bucket span=1h _time | stats dc(eval(process_resource&amp;gt;0)) as NumProcesses dc(eval(process_reaource=0)) as NumProcesses0 by _time&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 19:53:01 GMT</pubDate>
    <dc:creator>Runals</dc:creator>
    <dc:date>2020-09-28T19:53:01Z</dc:date>
    <item>
      <title>conditional distinct count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/conditional-distinct-count/m-p/185821#M53546</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Is there a way I can merge these two searches into a single conditional search?&lt;/P&gt;

&lt;P&gt;index="webs" (process_resource&amp;gt;0) AND (subs_id&amp;gt;0)| bucket _time span=1h |stats distinct_count(process_id) as NumProcesses by _time&lt;/P&gt;

&lt;P&gt;index="webs" (process_resource==0) AND (subs_id&amp;gt;0)| bucket _time span=1h |stats distinct_count(process_id) as NumProcesses0 by _time&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:52:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/conditional-distinct-count/m-p/185821#M53546</guid>
      <dc:creator>zahmadian</dc:creator>
      <dc:date>2020-09-28T19:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: conditional distinct count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/conditional-distinct-count/m-p/185822#M53547</link>
      <description>&lt;P&gt;Here you go with &lt;STRONG&gt;appendcols&lt;/STRONG&gt;!&lt;/P&gt;

&lt;P&gt;index="webs" (process_resource&amp;gt;0) subs_id&amp;gt;0| bucket _time span=1h |stats distinct_count(process_id) as NumProcesses by _time|appendcols [search  index="webs" (process_resource&amp;gt;0) subs_id&amp;gt;0| bucket _time span=1h |stats distinct_count(process_id) as NumProcesses0 by _time]|table _time NumProcesses NumProcesses0&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:52:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/conditional-distinct-count/m-p/185822#M53547</guid>
      <dc:creator>stephanefotso</dc:creator>
      <dc:date>2020-09-28T19:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: conditional distinct count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/conditional-distinct-count/m-p/185823#M53548</link>
      <description>&lt;P&gt;index = webs process_resource&amp;gt;=0 subs_id&amp;gt;0 | bucket span=1h _time | stats dc(eval(process_resource&amp;gt;0)) as NumProcesses dc(eval(process_reaource=0)) as NumProcesses0 by _time&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:53:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/conditional-distinct-count/m-p/185823#M53548</guid>
      <dc:creator>Runals</dc:creator>
      <dc:date>2020-09-28T19:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: conditional distinct count</title>
      <link>https://community.splunk.com/t5/Splunk-Search/conditional-distinct-count/m-p/185824#M53549</link>
      <description>&lt;P&gt;I suspect you want something like this.   It uses an eval command to make a new field on each event called "type".  For each event the value will be either "zero" or "greater than zero", depending.  Then we simply use timechart to render the chart you already had, except we split it by our new type field. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="webs" (process_resource&amp;gt;=0) AND (subs_id&amp;gt;0) 
| eval type=if(process_resource==0,"zero","greater_than_zero") 
| timechart span=1h distinct_count(process_id) by type
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 12 May 2015 05:35:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/conditional-distinct-count/m-p/185824#M53549</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2015-05-12T05:35:56Z</dc:date>
    </item>
  </channel>
</rss>

