Splunk Enterprise Security

Distinct Count combined with List

jacqu3sy
Path Finder

Is it possible to take a distinct count of something, then list this by an additional value by day?

something like the following but tweaked to display the count of events, by urgency on specific days;

notable
| bucket _time span=1d
| stats dc(event_id) by urgency, _time

The goal being a table that looks like the following;

Monday Medium, 5
High, 7
Tuesday Low, 6
Medium, 10
High, 20
etc etc

Thanks.

0 Karma
1 Solution

to4kawa
Ultra Champion
notable
| bucket _time span=1d
| chart dc(event_id) by date_wday urgency
| table date_wday, High, Medium, Low

Hi, @jacqu3sy
Please use chart.
Finally, the order of the columns must be aligned.

View solution in original post

0 Karma

to4kawa
Ultra Champion
notable
| bucket _time span=1d
| chart dc(event_id) by date_wday urgency
| table date_wday, High, Medium, Low

Hi, @jacqu3sy
Please use chart.
Finally, the order of the columns must be aligned.

0 Karma

jacqu3sy
Path Finder

great stuff. Many thanks.

0 Karma

TISKAR
Builder

Hi @jacqu3sy:

can you try this please:

notable
| bucket _time span=1d
| stats dc(event_id) by date_wday, urgency
0 Karma

jacqu3sy
Path Finder

Kinda, but I want to list the results for each day within it's own row, if that makes sense.

So that is display better, in a table with a row for Monday, then alongside it listed the count by urgency.

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...