Splunk Search

Distinct count higher than a value ?

atanasmitev
Path Finder

Hello all,

I am trying to search for distinct count higher than a value.
Below is what I tried, obfuscated :

stats dc(var1) as some_name by var2 which returns a column of values , say {1, 55, 2200, 45, 100, .. etc}
How do I extract from that column values higher than a "limit" ?

I tried

stats dc(var1) as some_name by var2 | search some_name > limit, but it doesn't work

Ideas ?

Tags (3)
1 Solution

lguinn2
Legend

If limit is a field, you can't use search - you need to use where

yoursearchhere
stats dc(var1) as some_name by var2 
| where some_name > limit

If limit is a literal, you can use either search or where

yoursearchhere
stats dc(var1) as some_name by var2 
| search some_name > 7

View solution in original post

lguinn2
Legend

If limit is a field, you can't use search - you need to use where

yoursearchhere
stats dc(var1) as some_name by var2 
| where some_name > limit

If limit is a literal, you can use either search or where

yoursearchhere
stats dc(var1) as some_name by var2 
| search some_name > 7

atanasmitev
Path Finder

Thanks, it worked like a charm, it seems I have to RTFM more often 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

[Puzzles] Solve, Learn, Repeat: Family Trees

This puzzle (first published here is based on finding grandparents and grandchildren (inspired by a question ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...