I have 191 events logged for a specific day.
When I do a
timechart span=1d count
I get count of 191 for that day as expected. But when trying to get a count of events split by a field
timechart span=1d count by userclass
the sum of columns generated according to the userclass add up to 194 (I have three userclasses, 100+26+68 = 194).
Is this a bug or am I missing something how the split-by clause works?
Do any events have multiple userclass values?
Here's a dummy example:
| stats count | eval userclass = "foo bar baz" | makemv userclass | stats count by userclass
This generates one event with three userclass values, giving you a total of three after the final stats.
Do any events have multiple userclass values?
Here's a dummy example:
| stats count | eval userclass = "foo bar baz" | makemv userclass | stats count by userclass
This generates one event with three userclass values, giving you a total of three after the final stats.
Done and done.
Yes, some of the userclass field values were multivalues by mistake. Thanks for the tip! Can you make an answer out of your comment, so I can accept it?