I have a working search that uses a look up, that is like this:
index=MyIndex
[| inputlookup MyCSVFile
| stats values(email) AS EmailAddress
| format]
|chart count(Code) as NumCodes over EmailAddress |sort -NumCodes
This works, but there are duplicate codes, so i want the search to count only unique codes per user.
I am not sure how to say Count Unique.
Thank you for your help!!
Splunk uses "distinct_count" for Count Unique.
index=MyIndex
[| inputlookup MyCSVFile
| stats values(email) AS EmailAddress
| format]
| chart distinct_count(Code) as NumCodes over EmailAddress
| sort - NumCodes
Splunk uses "distinct_count" for Count Unique.
index=MyIndex
[| inputlookup MyCSVFile
| stats values(email) AS EmailAddress
| format]
| chart distinct_count(Code) as NumCodes over EmailAddress
| sort - NumCodes