Splunk Search

Why doesn't the stramstats work when I group by certain field?

buttsurfer
Path Finder

The search below doesn't work when i add department in the group by fields in the streamstats commands. It works with any other field but this one. Can someone please give some insight?

 

 

 

index=...
| lookup lookup cn as user OUTPUT department
| reverse
| dedup department application feature time
| streamstats current=f window=1 values(currTotalCount) as prev_count by application feature department
| table department application user display time feature currTotalCount prev_count

 

 

 

The prev_count field is empty when i add the department in the group by fields (streamstats command), otherwise it shows the correct result.

Labels (3)
0 Karma
1 Solution

buttsurfer
Path Finder

Fixed it by adding global=false

View solution in original post

0 Karma

buttsurfer
Path Finder

Fixed it by adding global=false

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...