Getting Data In

many events for each user - how to see only one event from each user?

rechteklebe
Path Finder

Hello together,

i would like to see in a search the amount of affected user. Sometimes there are more events related to one user (e.g. user=12345).

I search for example for: index=123 ERROR user=*

Now i would like to see the amount of user who are affected. How can i not showing duplicate events of one user. I would like to see only one event from each user.

e.g

There are 7 events for user=12345

There are 7 events for user=23456



--> I would like to see only:

1 event for user 12345

1 event for user 23456

Please help me.

Thank you in advance!

Tags (2)
0 Karma
1 Solution

Ayn
Legend
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...