Splunk Search

Why doesn't the stramstats work when I group by certain field?

buttsurfer
Path Finder

The search below doesn't work when i add department in the group by fields in the streamstats commands. It works with any other field but this one. Can someone please give some insight?

 

 

 

index=...
| lookup lookup cn as user OUTPUT department
| reverse
| dedup department application feature time
| streamstats current=f window=1 values(currTotalCount) as prev_count by application feature department
| table department application user display time feature currTotalCount prev_count

 

 

 

The prev_count field is empty when i add the department in the group by fields (streamstats command), otherwise it shows the correct result.

Labels (3)
0 Karma
1 Solution

buttsurfer
Path Finder

Fixed it by adding global=false

View solution in original post

0 Karma

buttsurfer
Path Finder

Fixed it by adding global=false

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...