Splunk Search

Distinct count higher than a value ?

atanasmitev
Path Finder

Hello all,

I am trying to search for distinct count higher than a value.
Below is what I tried, obfuscated :

stats dc(var1) as some_name by var2 which returns a column of values , say {1, 55, 2200, 45, 100, .. etc}
How do I extract from that column values higher than a "limit" ?

I tried

stats dc(var1) as some_name by var2 | search some_name > limit, but it doesn't work

Ideas ?

Tags (3)
1 Solution

lguinn2
Legend

If limit is a field, you can't use search - you need to use where

yoursearchhere
stats dc(var1) as some_name by var2 
| where some_name > limit

If limit is a literal, you can use either search or where

yoursearchhere
stats dc(var1) as some_name by var2 
| search some_name > 7

View solution in original post

lguinn2
Legend

If limit is a field, you can't use search - you need to use where

yoursearchhere
stats dc(var1) as some_name by var2 
| where some_name > limit

If limit is a literal, you can use either search or where

yoursearchhere
stats dc(var1) as some_name by var2 
| search some_name > 7

atanasmitev
Path Finder

Thanks, it worked like a charm, it seems I have to RTFM more often 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...