I want to get below in single query
1. dc of field1 overall
2. dc of field2 by field1
| eventstats dc(field1) as dc_field1
| stats dc(field2) as dc_field2, max(dc_field1) by field1
exactly the way I wanted... thanks a ton
If your problem is resolved, then please click the "Accept as Solution" button to help future readers.
I want to get below in single query
1. dc of field1 overall
2. dc of field2 by field1