Splunk Search

Unique number of users

rashi83
Path Finder

Hi , I am running a query to get count of unique users like
| stats dc(user)

How do I get list of those unique users?

Tags (1)
0 Karma

gcusello
Esteemed Legend

Hi @rashi83,
Try this:

your_search
| dedup user
| sort user
| table user

Ciao.
Giuseppe

0 Karma

whrg
Motivator

Try this:

| stats values(user)

You can combine it with the distinct count like this

| stats values(user) as users dc(user) as usercount

Alternatively:

| stats count by user
0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...