Splunk Search

How to filter my search to only count the users that visited each location at least N number of times?

pm771
Communicator

We have a listing of travelers. Every event has the following two fields: USER and LOCATION.

I need a search that will calculate how many frequent travelers visited each location. By definition, frequent traveler is a user that traveled in a given time period at least n times.

If I wanted just a grand total of such users, then I would've written it as:

index=... sourcetype=... | stats count as num by USER | where num > n | stats count as Total

How do I restore an association between selected users and their respective locations?

It sounds like a job for eventstats but I could not come up with a working search.

0 Karma
1 Solution

sundareshr
Legend

See if this gets you what you need

 index=... sourcetype=... | eventstats count as num by USER | where num > n | stats dc(USER) as FT by LOCATION

View solution in original post

sundareshr
Legend

See if this gets you what you need

 index=... sourcetype=... | eventstats count as num by USER | where num > n | stats dc(USER) as FT by LOCATION

pm771
Communicator

Actually my requirements were: how many times frequent travelers visited each location, so I dd not need distinct count.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...