Splunk Search

combine stats count and stats first

Path Finder

How do i combine these stats commands?

1)

| stats count by user host

creates table:

user host count

2)

| stats first(_time) AS latest by user host

creates table:

user host latest

How do i combine to create a table

user host latest count
Tags (4)
1 Solution

Motivator

This?

| stats count, first(_time) AS latest by user host

??

View solution in original post

Motivator

This?

| stats count, first(_time) AS latest by user host

??

View solution in original post

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!