Dashboards & Visualizations

Counting unique values per session ID

rsAU
Explorer

I'm trying to count the unique values of a field by the common ID (session ID) but only once (one event). Each sessionID could have multiples of each unique field value.

Initially I was getting the count of every event which isn't what I want to count and if I 'dedup' the sessionID then I only get one of the unique field values back. 

Is it possible to count one event per session ID for each unique field value? 

"stats values("field") by sessionID"  gets me close but in the table it lists the sessionIDs whereas I'm hoping to get the number (count) of unique sessionIDs 

FieldsessionID
value1

ABC123

123ABC

value2ABC123
value3123ABC
value4

ABC123

123ABC

AABBCC

12AB3C

value5

ABC123

123ABC

AABBCC

12AB3C

CBA321

 

Hopefully that makes sense. Thanks

 

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

You question is a little confusing as the table shows the values of sessionID by field, which is what you say you wanted, but the stats is giving the values of field by sessionID, i.e. the other way round.

Are you looking for dc, i.e.

| stats dc(sessionID) as uniqueSessionCount by field

which would give you the count of different sessionIDs for each value of "field"

View solution in original post

rsAU
Explorer

Thanks - this is what I was after!

Yeah I was getting a list of every sessionId but I was trying to find a way to get a count of each unique ID. 

Cheers, Ryan

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats dc(field) by sessionID
0 Karma

bowesmana
SplunkTrust
SplunkTrust

You question is a little confusing as the table shows the values of sessionID by field, which is what you say you wanted, but the stats is giving the values of field by sessionID, i.e. the other way round.

Are you looking for dc, i.e.

| stats dc(sessionID) as uniqueSessionCount by field

which would give you the count of different sessionIDs for each value of "field"

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...