Dashboards & Visualizations

Find highest and lowest value from split by two fields

Justinboucher0
Path Finder

I'm using the Splunk sample tutorial data and I want to figure out how to find the best selling and worst selling product by a specific product_name and country. Here is my current search:

 

index="tutorial" sourcetype="access_combined_wcookie" "action=purchase" 
| iplocation clientip 
| eventstats count as units_sold by product_name Country

 

 However, if I just do a min and max in the next stats command I don't really get the associated product_name or I don't get the Country as well. My expected result is:

CountryBest Selling

Worst Selling

United StatesProduct1

Product6

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Would something like this work?

index="tutorial" sourcetype="access_combined_wcookie" "action=purchase" 
| iplocation clientip 
| stats count as units_sold by product_name Country
| sort Country units_sold
| stats first(product_name) as worse_selling last(product_name) as best_selling by Country

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Would something like this work?

index="tutorial" sourcetype="access_combined_wcookie" "action=purchase" 
| iplocation clientip 
| stats count as units_sold by product_name Country
| sort Country units_sold
| stats first(product_name) as worse_selling last(product_name) as best_selling by Country
0 Karma

Justinboucher0
Path Finder

I'm an idiot. I didn't even think about first and last. I got tunnel vision on the units_sold. TY

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...