Splunk Search

combine stats count and stats first

r999
Path Finder

How do i combine these stats commands?

1)

| stats count by user host

creates table:

user host count

2)

| stats first(_time) AS latest by user host

creates table:

user host latest

How do i combine to create a table

user host latest count
Tags (4)
1 Solution

gfuente
Motivator

This?

| stats count, first(_time) AS latest by user host

??

View solution in original post

gfuente
Motivator

This?

| stats count, first(_time) AS latest by user host

??

*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>