Splunk Search
Highlighted

Count uniqe values over a certain period of time

Path Finder

Hi

I´m trying to create a search that basically count the number of unique UserId generated over a certain time in the userlog, the UserId consist of 5 digits for example 12345 or 79365 etc.. need help to finalize it.

The search begins like this...
index=main sourcetype=userlog UserId="*" | ...?

regards
Magnus

Tags (1)
0 Karma
Highlighted

Re: Count uniqe values over a certain period of time

Motivator

| stats dc(UserId) should do the trick for you.

View solution in original post

Highlighted

Re: Count uniqe values over a certain period of time

Path Finder

Thanks a lot, that worked.
/Magnus

0 Karma