<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Clarification regarding search command and stats command in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Clarification-regarding-search-command-and-stats-command/m-p/206873#M60267</link>
    <description>&lt;P&gt;Hey everyone,&lt;/P&gt;

&lt;P&gt;I'm confused about what the second command in my search does. Here is the whole search:&lt;/P&gt;

&lt;P&gt;| &lt;CODE&gt;useraccounts_tracker&lt;/CODE&gt; | search user_category=default | stats max(lastTime) as _time, values(user_category) as user_category, dc(dest) as dc(dest) by user | sort 100 - _time | fields _time,user,user_category,dc(dest)&lt;/P&gt;

&lt;P&gt;Specifically what I'm unsure about:&lt;BR /&gt;
-What does the search user_category=default command do? &lt;BR /&gt;
-What does the stats max(lastTime) as _time, values(user_category) as user_category, dc(dest) as dc(dest) by user command do? I know when it says "as" it's renaming  fields. So other than that, what is it doing? &lt;/P&gt;

&lt;P&gt;Any help would be appreciated!&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 11:04:49 GMT</pubDate>
    <dc:creator>Justin1224</dc:creator>
    <dc:date>2020-09-29T11:04:49Z</dc:date>
    <item>
      <title>Clarification regarding search command and stats command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Clarification-regarding-search-command-and-stats-command/m-p/206873#M60267</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;

&lt;P&gt;I'm confused about what the second command in my search does. Here is the whole search:&lt;/P&gt;

&lt;P&gt;| &lt;CODE&gt;useraccounts_tracker&lt;/CODE&gt; | search user_category=default | stats max(lastTime) as _time, values(user_category) as user_category, dc(dest) as dc(dest) by user | sort 100 - _time | fields _time,user,user_category,dc(dest)&lt;/P&gt;

&lt;P&gt;Specifically what I'm unsure about:&lt;BR /&gt;
-What does the search user_category=default command do? &lt;BR /&gt;
-What does the stats max(lastTime) as _time, values(user_category) as user_category, dc(dest) as dc(dest) by user command do? I know when it says "as" it's renaming  fields. So other than that, what is it doing? &lt;/P&gt;

&lt;P&gt;Any help would be appreciated!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:04:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Clarification-regarding-search-command-and-stats-command/m-p/206873#M60267</guid>
      <dc:creator>Justin1224</dc:creator>
      <dc:date>2020-09-29T11:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification regarding search command and stats command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Clarification-regarding-search-command-and-stats-command/m-p/206874#M60268</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;| `useraccounts_tracker` ---&amp;gt;  generating/fetching data. Need to know the macro definition to know source of the data
| search user_category=default ---&amp;gt; From the fetched data, filtering result which satisfy the filter condition (value of user_category is default
| stats max(lastTime) as _time, values(user_category) as user_category, dc(dest) as dc(dest) by user ----&amp;gt; From the filtered results, generate statistics, group by field user, to get max of field lastTime and rename as field _time, list all uniue values of the field user_category as itself, get distinct count of field dest as field "dc(dest)".
| sort 100 - _time  ---&amp;gt; sort the results from stats command in descending order of field _time and select first 100 records
| fields _time,user,user_category,dc(dest) ---&amp;gt; selecting only the required fields and setting the order of the display.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 22 Sep 2016 19:33:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Clarification-regarding-search-command-and-stats-command/m-p/206874#M60268</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-09-22T19:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification regarding search command and stats command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Clarification-regarding-search-command-and-stats-command/m-p/206875#M60269</link>
      <description>&lt;P&gt;That helps a lot, thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2016 14:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Clarification-regarding-search-command-and-stats-command/m-p/206875#M60269</guid>
      <dc:creator>Justin1224</dc:creator>
      <dc:date>2016-09-23T14:55:48Z</dc:date>
    </item>
  </channel>
</rss>

