Dashboards & Visualizations

Counting unique values per session ID

rsAU
Explorer

I'm trying to count the unique values of a field by the common ID (session ID) but only once (one event). Each sessionID could have multiples of each unique field value.

Initially I was getting the count of every event which isn't what I want to count and if I 'dedup' the sessionID then I only get one of the unique field values back. 

Is it possible to count one event per session ID for each unique field value? 

"stats values("field") by sessionID"  gets me close but in the table it lists the sessionIDs whereas I'm hoping to get the number (count) of unique sessionIDs 

FieldsessionID
value1

ABC123

123ABC

value2ABC123
value3123ABC
value4

ABC123

123ABC

AABBCC

12AB3C

value5

ABC123

123ABC

AABBCC

12AB3C

CBA321

 

Hopefully that makes sense. Thanks

 

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

You question is a little confusing as the table shows the values of sessionID by field, which is what you say you wanted, but the stats is giving the values of field by sessionID, i.e. the other way round.

Are you looking for dc, i.e.

| stats dc(sessionID) as uniqueSessionCount by field

which would give you the count of different sessionIDs for each value of "field"

View solution in original post

rsAU
Explorer

Thanks - this is what I was after!

Yeah I was getting a list of every sessionId but I was trying to find a way to get a count of each unique ID. 

Cheers, Ryan

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats dc(field) by sessionID
0 Karma

bowesmana
SplunkTrust
SplunkTrust

You question is a little confusing as the table shows the values of sessionID by field, which is what you say you wanted, but the stats is giving the values of field by sessionID, i.e. the other way round.

Are you looking for dc, i.e.

| stats dc(sessionID) as uniqueSessionCount by field

which would give you the count of different sessionIDs for each value of "field"

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...