Splunk Dev

How to identify uniqe field value from a log files

dilstn
Explorer

there is a logs that as same timestamp , in which i have to identify the unique user id from the logs (i,e) I have to create count of users logged in (unique user entry) count

Tags (1)
0 Karma

eashwar
Communicator

<\yoursearch> | dedup userid | stats count AS "TOTAL Number of Users Logged in"

or

<\yoursearch> | stats count by userid

<\yoursearch> should have the field userid extracted out from the event. you should comment the event so that i can help you in extraction.

happy splunking
yours,
eashwar raghunathan

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Telepathy tells me rex "whatever" | stats dc(user_id)... beyond that, what Ayn said.

0 Karma

Ayn
Legend

Please give us MUCH more details about the logs, what you're trying to do, what you tried but didn't work, etc etc...

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...