Splunk Search

count of events in a day per user as one

eswar89788
New Member

Hi

I have specific capability built for my users group. I am calculating events based on the service calls per user. found an anamoly that
there are 5000 events in one day on one capability per user which is incorrect. so i decided to group all the events occurred in a day per user specific to each capability and count as 1 instead of 5000. Tried different like below but no luck. can some one help to solve this ?

stats count by users
stats count by users,time

0 Karma

to4kawa
Ultra Champion

so i decided to group all the events occurred in a day per user specific to each capability and count as 1
How?
There is no sample, you should make query by your self.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share your searches.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...