Hi ,
I am trying to run a splunk query and i am able to generate the required filed . however i am facing difficulties in replicating the same using stats under statistics table
For example ,
Under selected filed , I was able to retrieve the required fields , lets say User, host, IP, LP and session
When i use the below command
stats values(User) AS user , values(host) AS host, values(LP) AS LP, values(IP) AS IP BY session
Session is common and appears for all.
But i am able to see only host , session , LP values under statistics but user and IP values are not being displayed although they are available under the selected field. ( when you look into events tab)
Any help would be appreciated !!