My application logs transaction data into Splunk, and from it, I know what user is performing what transaction.
Example : Sometimes, in a 15 min span, there are are just 2 users with 30 transactions.
I want to be able to know the total distinct user count in a span of 15 min over a period of one week.
hope i understand the question,
if your field for user is: "user"
try something along those lines:
... | timechart dc(user) as unique_users span=15m
hope i understand the question,
if your field for user is: "user"
try something along those lines:
... | timechart dc(user) as unique_users span=15m
This helps. Thank you.
Accept the answer if it helped you...