Splunk Search

count of events in a day per user as one

eswar89788
New Member

Hi

I have specific capability built for my users group. I am calculating events based on the service calls per user. found an anamoly that
there are 5000 events in one day on one capability per user which is incorrect. so i decided to group all the events occurred in a day per user specific to each capability and count as 1 instead of 5000. Tried different like below but no luck. can some one help to solve this ?

stats count by users
stats count by users,time

0 Karma

to4kawa
Ultra Champion

so i decided to group all the events occurred in a day per user specific to each capability and count as 1
How?
There is no sample, you should make query by your self.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share your searches.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...