Splunk Search

count of events in a day per user as one

eswar89788
New Member

Hi

I have specific capability built for my users group. I am calculating events based on the service calls per user. found an anamoly that
there are 5000 events in one day on one capability per user which is incorrect. so i decided to group all the events occurred in a day per user specific to each capability and count as 1 instead of 5000. Tried different like below but no luck. can some one help to solve this ?

stats count by users
stats count by users,time

0 Karma

to4kawa
Ultra Champion

so i decided to group all the events occurred in a day per user specific to each capability and count as 1
How?
There is no sample, you should make query by your self.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share your searches.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...