Splunk Search

How to accum a field extra for each user?

p_splunk
Engager

Hi,

i want to accumulate a field per user (and time).

so lets say the users are distinguishable by the field user and the field i want to accumulate per user is XP.

if i do smth like

...| sort 0 +_time | stats c(user) as XPgains by user | accum XP as accumXP

I see in the list of logevents that the function accumulates over all users beginnining from first time event to the very last and the accum fct doesn't take any "by user" or smth like this.

how can I get a field which starts counting new for every user?

Tags (1)
0 Karma
1 Solution

Ayn
Legend

Use streamstats instead:

... | streamstats count by user AS accumXP

View solution in original post

Ayn
Legend

Use streamstats instead:

... | streamstats count by user AS accumXP
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...