I have a search where I am trying to determine if a sender is a threat based on several different events that are added up at the end of my search. Before that though im trying to determine how many people that a sender has sent a message too. So far ive tried mvcount but it looks like mvcount doesnt allow a count by another value. Thanks in advance.
It appears that you posted this same question twice, is this one a duplicate of this one:
If so, you should delete this one, because the other answer is more specific and has an accepted answer.
you can use the
eventstats command, read here:
try this search anywhere, i hope it explains it well:
| makeresults count=5 | eval sender = "badguy,goodguy,neutralguy" | makemv delim="," sender | mvexpand sender | eval recipients = case(sender=="badguy","1;;;2;;;3;;;4;;;5",sender=="neutralguy","1;;;2;;;3",sender=="goodguy","1") | makemv delim=";;;" recipients | mvexpand recipients | eval message = "random message" | eventstats dc(recipients) as unique_recipients by sender
Im not wanting to use stats because im needing to just count the number of recipients by sender mid search and from what ive tried I havent had much success from it. Im completly open if there is a way to do it.