Splunk Search

Why doesn't the stramstats work when I group by certain field?

buttsurfer
Path Finder

The search below doesn't work when i add department in the group by fields in the streamstats commands. It works with any other field but this one. Can someone please give some insight?

 

 

 

index=...
| lookup lookup cn as user OUTPUT department
| reverse
| dedup department application feature time
| streamstats current=f window=1 values(currTotalCount) as prev_count by application feature department
| table department application user display time feature currTotalCount prev_count

 

 

 

The prev_count field is empty when i add the department in the group by fields (streamstats command), otherwise it shows the correct result.

Labels (4)
0 Karma
1 Solution

buttsurfer
Path Finder

Fixed it by adding global=false

View solution in original post

0 Karma

buttsurfer
Path Finder

Fixed it by adding global=false

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...