Splunk Enterprise Security

Distinct Count combined with List

jacqu3sy
Path Finder

Is it possible to take a distinct count of something, then list this by an additional value by day?

something like the following but tweaked to display the count of events, by urgency on specific days;

notable
| bucket _time span=1d
| stats dc(event_id) by urgency, _time

The goal being a table that looks like the following;

Monday Medium, 5
High, 7
Tuesday Low, 6
Medium, 10
High, 20
etc etc

Thanks.

0 Karma
1 Solution

to4kawa
Ultra Champion
notable
| bucket _time span=1d
| chart dc(event_id) by date_wday urgency
| table date_wday, High, Medium, Low

Hi, @jacqu3sy
Please use chart.
Finally, the order of the columns must be aligned.

View solution in original post

0 Karma

to4kawa
Ultra Champion
notable
| bucket _time span=1d
| chart dc(event_id) by date_wday urgency
| table date_wday, High, Medium, Low

Hi, @jacqu3sy
Please use chart.
Finally, the order of the columns must be aligned.

0 Karma

jacqu3sy
Path Finder

great stuff. Many thanks.

0 Karma

TISKAR
Builder

Hi @jacqu3sy:

can you try this please:

notable
| bucket _time span=1d
| stats dc(event_id) by date_wday, urgency
0 Karma

jacqu3sy
Path Finder

Kinda, but I want to list the results for each day within it's own row, if that makes sense.

So that is display better, in a table with a row for Monday, then alongside it listed the count by urgency.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...