Splunk Search
Highlighted

combine stats count and stats first

Path Finder

How do i combine these stats commands?

1)

| stats count by user host

creates table:

user host count

2)

| stats first(_time) AS latest by user host

creates table:

user host latest

How do i combine to create a table

user host latest count
Tags (4)
Highlighted

Re: combine stats count and stats first

Motivator

This?

| stats count, first(_time) AS latest by user host

??

View solution in original post