Splunk Search

How to filter my search to only count the users that visited each location at least N number of times?

pm771
Communicator

We have a listing of travelers. Every event has the following two fields: USER and LOCATION.

I need a search that will calculate how many frequent travelers visited each location. By definition, frequent traveler is a user that traveled in a given time period at least n times.

If I wanted just a grand total of such users, then I would've written it as:

index=... sourcetype=... | stats count as num by USER | where num > n | stats count as Total

How do I restore an association between selected users and their respective locations?

It sounds like a job for eventstats but I could not come up with a working search.

0 Karma
1 Solution

sundareshr
Legend

See if this gets you what you need

 index=... sourcetype=... | eventstats count as num by USER | where num > n | stats dc(USER) as FT by LOCATION

View solution in original post

sundareshr
Legend

See if this gets you what you need

 index=... sourcetype=... | eventstats count as num by USER | where num > n | stats dc(USER) as FT by LOCATION

pm771
Communicator

Actually my requirements were: how many times frequent travelers visited each location, so I dd not need distinct count.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...