Splunk Search

Why doesn't the stramstats work when I group by certain field?

buttsurfer
Path Finder

The search below doesn't work when i add department in the group by fields in the streamstats commands. It works with any other field but this one. Can someone please give some insight?

 

 

 

index=...
| lookup lookup cn as user OUTPUT department
| reverse
| dedup department application feature time
| streamstats current=f window=1 values(currTotalCount) as prev_count by application feature department
| table department application user display time feature currTotalCount prev_count

 

 

 

The prev_count field is empty when i add the department in the group by fields (streamstats command), otherwise it shows the correct result.

Labels (3)
0 Karma
1 Solution

buttsurfer
Path Finder

Fixed it by adding global=false

View solution in original post

0 Karma

buttsurfer
Path Finder

Fixed it by adding global=false

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...