Hi,
Here's my query:
index=uplynk slice_played isLive=1 channelID=8f88881faa334ab59484e999c6c5c318 | stats dc(playerUserAgent) as "Count of Unique User Agents" by sessionID
This gives me a distinct count of playerUserAgent by sessionID. However, in the resulting statistics table, I not only want the sessionID and "Count of Unique User Agents", but also the comma separated values of playerUserAgent. I've tried using mv commands but with no success. Please help!
index=uplynk slice_played isLive=1 channelID=8f88881faa334ab59484e999c6c5c318 | stats dc(playerUserAgent) as "Count of Unique User Agents", values(playerUserAgent) as useragents by sessionID | eval useragents = mvjoin(useragents, ",")
@moizmmz
Try this.
index=uplynk slice_played isLive=1 channelID=8f88881faa334ab59484e999c6c5c318
| stats delim="," dc(playerUserAgent) as "Count of Unique User Agents", values(playerUserAgent) as useragents by sessionID
| nomv useragents
Here, I have used delim
in stats
and nomv
.
Ref:
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/stats
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/nomv
This works too 🙂 thank you!!
Sorry I could only accept one answer. But I'll send you some points. Thanks for your help!
index=uplynk slice_played isLive=1 channelID=8f88881faa334ab59484e999c6c5c318 | stats dc(playerUserAgent) as "Count of Unique User Agents", values(playerUserAgent) as useragents by sessionID | eval useragents = mvjoin(useragents, ",")
This works! Thank you 🙂