- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
debjit_k
Path Finder
10-17-2022
10:07 AM
Hi
Hope you are doing good..
I want to build one query where I will get user with associate event code or IP for example
If I use stats count by user, event code
I will get
User event code
Abc 1
Abc 2
But I want output like
User event code
Abc 1, 2
I.e. User name should not get repeat for different event code
Can you please guide me here
Thanks
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gcusello

SplunkTrust
10-17-2022
10:31 PM
Hi @debjit_k,
you should use values in your stats command, something like this:
<your_search>
| stats values(EventCode) AS EventCode values(ip) AS ip BY user
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
debjit_k
Path Finder
10-19-2022
05:12 AM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gcusello

SplunkTrust
10-19-2022
05:36 AM
Hi @debjit_k,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gcusello

SplunkTrust
10-17-2022
10:31 PM
Hi @debjit_k,
you should use values in your stats command, something like this:
<your_search>
| stats values(EventCode) AS EventCode values(ip) AS ip BY user
Ciao.
Giuseppe
