 
					
				
		
We have a listing of travelers. Every event has the following two fields: USER and LOCATION.
I need a search that will calculate how many frequent travelers visited each location.  By definition, frequent traveler is a user that traveled  in a given time period at least n times.
If I wanted just a grand total of such users, then I would've written it as:
index=... sourcetype=... | stats count as num by USER | where num > n | stats count as Total
How do I restore an association between selected users and their respective locations?
It sounds like a job for eventstats but I could not come up with a working search.
 
					
				
		
See if this gets you what you need
 index=... sourcetype=... | eventstats count as num by USER | where num > n | stats dc(USER) as FT by LOCATION
 
					
				
		
See if this gets you what you need
 index=... sourcetype=... | eventstats count as num by USER | where num > n | stats dc(USER) as FT by LOCATION
 
					
				
		
Actually my requirements were: how many times frequent travelers visited each location, so I dd not need distinct count.
