Splunk Search

How to group results that has 5 or more distinct values in list(repo_name) ?

wailoont
Engager

Hi,

I have a search query as below.

query | stats list(repo_name) by user_login

This returns username with their repository listed grouped by the user_login.

For example :

Name Repository
user_login XXX

How can i enhance the query to only return searches ONLY if the list of repository has 5 or more values ?

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Perhaps something like this will work for you.

query | stats list(repo_name) as repo_names by user_login | where mvcount(repo_names) > 4
---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps something like this will work for you.

query | stats list(repo_name) as repo_names by user_login | where mvcount(repo_names) > 4
---
If this reply helps you, Karma would be appreciated.
0 Karma

wailoont
Engager

Many thanks. it works. 🙂

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...