Dashboards & Visualizations

Counting unique values per session ID

rsAU
Explorer

I'm trying to count the unique values of a field by the common ID (session ID) but only once (one event). Each sessionID could have multiples of each unique field value.

Initially I was getting the count of every event which isn't what I want to count and if I 'dedup' the sessionID then I only get one of the unique field values back. 

Is it possible to count one event per session ID for each unique field value? 

"stats values("field") by sessionID"  gets me close but in the table it lists the sessionIDs whereas I'm hoping to get the number (count) of unique sessionIDs 

FieldsessionID
value1

ABC123

123ABC

value2ABC123
value3123ABC
value4

ABC123

123ABC

AABBCC

12AB3C

value5

ABC123

123ABC

AABBCC

12AB3C

CBA321

 

Hopefully that makes sense. Thanks

 

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

You question is a little confusing as the table shows the values of sessionID by field, which is what you say you wanted, but the stats is giving the values of field by sessionID, i.e. the other way round.

Are you looking for dc, i.e.

| stats dc(sessionID) as uniqueSessionCount by field

which would give you the count of different sessionIDs for each value of "field"

View solution in original post

rsAU
Explorer

Thanks - this is what I was after!

Yeah I was getting a list of every sessionId but I was trying to find a way to get a count of each unique ID. 

Cheers, Ryan

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats dc(field) by sessionID
0 Karma

bowesmana
SplunkTrust
SplunkTrust

You question is a little confusing as the table shows the values of sessionID by field, which is what you say you wanted, but the stats is giving the values of field by sessionID, i.e. the other way round.

Are you looking for dc, i.e.

| stats dc(sessionID) as uniqueSessionCount by field

which would give you the count of different sessionIDs for each value of "field"

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...