Splunk Dev

How to identify uniqe field value from a log files

dilstn
Explorer

there is a logs that as same timestamp , in which i have to identify the unique user id from the logs (i,e) I have to create count of users logged in (unique user entry) count

Tags (1)
0 Karma

eashwar
Communicator

<\yoursearch> | dedup userid | stats count AS "TOTAL Number of Users Logged in"

or

<\yoursearch> | stats count by userid

<\yoursearch> should have the field userid extracted out from the event. you should comment the event so that i can help you in extraction.

happy splunking
yours,
eashwar raghunathan

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Telepathy tells me rex "whatever" | stats dc(user_id)... beyond that, what Ayn said.

0 Karma

Ayn
Legend

Please give us MUCH more details about the logs, what you're trying to do, what you tried but didn't work, etc etc...

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...