Dashboards & Visualizations

Counting unique values per session ID

rsAU
Explorer

I'm trying to count the unique values of a field by the common ID (session ID) but only once (one event). Each sessionID could have multiples of each unique field value.

Initially I was getting the count of every event which isn't what I want to count and if I 'dedup' the sessionID then I only get one of the unique field values back. 

Is it possible to count one event per session ID for each unique field value? 

"stats values("field") by sessionID"  gets me close but in the table it lists the sessionIDs whereas I'm hoping to get the number (count) of unique sessionIDs 

FieldsessionID
value1

ABC123

123ABC

value2ABC123
value3123ABC
value4

ABC123

123ABC

AABBCC

12AB3C

value5

ABC123

123ABC

AABBCC

12AB3C

CBA321

 

Hopefully that makes sense. Thanks

 

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

You question is a little confusing as the table shows the values of sessionID by field, which is what you say you wanted, but the stats is giving the values of field by sessionID, i.e. the other way round.

Are you looking for dc, i.e.

| stats dc(sessionID) as uniqueSessionCount by field

which would give you the count of different sessionIDs for each value of "field"

View solution in original post

rsAU
Explorer

Thanks - this is what I was after!

Yeah I was getting a list of every sessionId but I was trying to find a way to get a count of each unique ID. 

Cheers, Ryan

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats dc(field) by sessionID
0 Karma

bowesmana
SplunkTrust
SplunkTrust

You question is a little confusing as the table shows the values of sessionID by field, which is what you say you wanted, but the stats is giving the values of field by sessionID, i.e. the other way round.

Are you looking for dc, i.e.

| stats dc(sessionID) as uniqueSessionCount by field

which would give you the count of different sessionIDs for each value of "field"

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...