Dashboards & Visualizations

Counting unique values per session ID

rsAU
Explorer

I'm trying to count the unique values of a field by the common ID (session ID) but only once (one event). Each sessionID could have multiples of each unique field value.

Initially I was getting the count of every event which isn't what I want to count and if I 'dedup' the sessionID then I only get one of the unique field values back. 

Is it possible to count one event per session ID for each unique field value? 

"stats values("field") by sessionID"  gets me close but in the table it lists the sessionIDs whereas I'm hoping to get the number (count) of unique sessionIDs 

FieldsessionID
value1

ABC123

123ABC

value2ABC123
value3123ABC
value4

ABC123

123ABC

AABBCC

12AB3C

value5

ABC123

123ABC

AABBCC

12AB3C

CBA321

 

Hopefully that makes sense. Thanks

 

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

You question is a little confusing as the table shows the values of sessionID by field, which is what you say you wanted, but the stats is giving the values of field by sessionID, i.e. the other way round.

Are you looking for dc, i.e.

| stats dc(sessionID) as uniqueSessionCount by field

which would give you the count of different sessionIDs for each value of "field"

View solution in original post

rsAU
Explorer

Thanks - this is what I was after!

Yeah I was getting a list of every sessionId but I was trying to find a way to get a count of each unique ID. 

Cheers, Ryan

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| stats dc(field) by sessionID
0 Karma

bowesmana
SplunkTrust
SplunkTrust

You question is a little confusing as the table shows the values of sessionID by field, which is what you say you wanted, but the stats is giving the values of field by sessionID, i.e. the other way round.

Are you looking for dc, i.e.

| stats dc(sessionID) as uniqueSessionCount by field

which would give you the count of different sessionIDs for each value of "field"

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...