Hi,
I'm struggling with a simple search.
I have multiple events for the same username. I need to count the number of usernames that appeared in those events. I start with just 1 day when there should be only 1 username. But this search returns the count of 7, because it counts events, not usernames, even though I put the username field in the count command:
index=* policy_name=* | stats count(username)
I tried adding dedup before stats, but it didn't do anything. What am I missing, please?
Thanks,
Alina
Try this
| stats dc(username)
That's it.
Thanks