Splunk Search

count of events in a day per user as one

eswar89788
New Member

Hi

I have specific capability built for my users group. I am calculating events based on the service calls per user. found an anamoly that
there are 5000 events in one day on one capability per user which is incorrect. so i decided to group all the events occurred in a day per user specific to each capability and count as 1 instead of 5000. Tried different like below but no luck. can some one help to solve this ?

stats count by users
stats count by users,time

0 Karma

to4kawa
Ultra Champion

so i decided to group all the events occurred in a day per user specific to each capability and count as 1
How?
There is no sample, you should make query by your self.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share your searches.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...