I have a log output which provides many fields, but the two I'm most concerned with are user and device.
I'm trying to output a list of users and devices which corresponds with the user from the log data, only in the event that the user has more than one device associated: I.e.:
I don't care about users who have only one device assigned, and want to focus on users where the distinct count of devices >1.
Can you try this if you have fields called
device to return all the users who have more than once device:
your base query to return you the user and device field | table user, device | stats count by user | where count > 1
your base query to return you the user and device field | stats values(device) as Devices, dc(device) as DevicesHeld by user | where DevicesHeld > 1
This was a good solution, but the other was a little simpler. Thanks for your time!
base search | stats values(device) as devices by user | where mvcount(devices)>1