We have a listing of travelers. Every event has the following two fields: USER and LOCATION.
I need a search that will calculate how many frequent travelers visited each location. By definition, frequent traveler is a user that traveled in a given time period at least n times.
If I wanted just a grand total of such users, then I would've written it as:
index=... sourcetype=... | stats count as num by USER | where num > n | stats count as Total
How do I restore an association between selected users and their respective locations?
It sounds like a job for eventstats but I could not come up with a working search.
See if this gets you what you need
index=... sourcetype=... | eventstats count as num by USER | where num > n | stats dc(USER) as FT by LOCATION
View solution in original post
Actually my requirements were: how many times frequent travelers visited each location, so I dd not need distinct count.