Splunk Search

How to edit my search to group by multiple values?

ewanbrown
Path Finder

I have a search in which I want to return the distinct number of users doing an number of actions b1 - b5 split by platform (web & mobile)

This search does not work which makes sense, but is there a way in one search I can get 10 numbers?

index=beacon Platform=mobile OR Platform=web | stats dc(USERID) by Platform, b1, b2, b3, b4, b5

mobile b1 123
mobile b2 567
.. 
mobile b5 234
web    b1 236
--
--
web    b5 876

Thanks

0 Karma

woodcock
Esteemed Legend

Like this:

index=beacon Platform=mobile OR Platform=web | chart dc(USERID) over Action by Platform
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...