Splunk Search

Using stats command to return 0 value

mdeterville
Path Finder

Hi There:

I'm trying to return the list of access_users with 0 web hits from the web_hits table. 

How can i adjust this query to return the list of users with no hits from the web_hits table?

Thanks in advance!

 

| inputlookup web_hits.csv

| lookup local=t access_users.csv user OUTPUT user as access_user

| search access_user="*"

| stats count as num_webhits by access_user


Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The stats command can't count what isn't there so you won't get a zero.  This query returns those access_users that are not in the web_hits table.

| inputlookup local=t access_users.csv where NOT [| inputlookup web_hits.csv | fields user | rename user as access_user | format ]

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...