Dashboards & Visualizations

Find highest and lowest value from split by two fields

Justinboucher0
Path Finder

I'm using the Splunk sample tutorial data and I want to figure out how to find the best selling and worst selling product by a specific product_name and country. Here is my current search:

 

index="tutorial" sourcetype="access_combined_wcookie" "action=purchase" 
| iplocation clientip 
| eventstats count as units_sold by product_name Country

 

 However, if I just do a min and max in the next stats command I don't really get the associated product_name or I don't get the Country as well. My expected result is:

CountryBest Selling

Worst Selling

United StatesProduct1

Product6

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Would something like this work?

index="tutorial" sourcetype="access_combined_wcookie" "action=purchase" 
| iplocation clientip 
| stats count as units_sold by product_name Country
| sort Country units_sold
| stats first(product_name) as worse_selling last(product_name) as best_selling by Country

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Would something like this work?

index="tutorial" sourcetype="access_combined_wcookie" "action=purchase" 
| iplocation clientip 
| stats count as units_sold by product_name Country
| sort Country units_sold
| stats first(product_name) as worse_selling last(product_name) as best_selling by Country
0 Karma

Justinboucher0
Path Finder

I'm an idiot. I didn't even think about first and last. I got tunnel vision on the units_sold. TY

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...