i want to accumulate a field per user (and time).
so lets say the users are distinguishable by the field user and the field i want to accumulate per user is XP.
if i do smth like
...| sort 0 +_time | stats c(user) as XPgains by user | accum XP as accumXP
I see in the list of logevents that the function accumulates over all users beginnining from first time event to the very last and the accum fct doesn't take any "by user" or smth like this.
how can I get a field which starts counting new for every user?
Use streamstats instead:
... | streamstats count by user AS accumXP
View solution in original post