Splunk Search

Distinct count higher than a value ?

atanasmitev
Path Finder

Hello all,

I am trying to search for distinct count higher than a value.
Below is what I tried, obfuscated :

stats dc(var1) as some_name by var2 which returns a column of values , say {1, 55, 2200, 45, 100, .. etc}
How do I extract from that column values higher than a "limit" ?

I tried

stats dc(var1) as some_name by var2 | search some_name > limit, but it doesn't work

Ideas ?

Tags (3)
1 Solution

lguinn2
Legend

If limit is a field, you can't use search - you need to use where

yoursearchhere
stats dc(var1) as some_name by var2 
| where some_name > limit

If limit is a literal, you can use either search or where

yoursearchhere
stats dc(var1) as some_name by var2 
| search some_name > 7

View solution in original post

lguinn2
Legend

If limit is a field, you can't use search - you need to use where

yoursearchhere
stats dc(var1) as some_name by var2 
| where some_name > limit

If limit is a literal, you can use either search or where

yoursearchhere
stats dc(var1) as some_name by var2 
| search some_name > 7

atanasmitev
Path Finder

Thanks, it worked like a charm, it seems I have to RTFM more often 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Improve Delivery Assurance with S2S ACK for Edge Processor

Edge Processor helps Splunk customers process data closer to the source: filtering, transforming, masking, and ...

.conf26 Platform Sessions: Turn Machine Data into Agentic Action

As autonomous agents and multi-cloud architectures reshape modern IT, data platforms have to do far more than ...

Introducing the Launch of Edge Processor in Hybrid Mode!

Modernize Data Ingestion Without Starting Over  For years, organizations have relied on Splunk's proven ...