Splunk Search

distinct count not working on summary index (sistats)

loganramirez
Path Finder

Splunk Enterprise 9.0.6 and building a summary index of sourcenumbers (count) and distinct destinations called (dc(destinationnumber))

When i run this:

...
| stats count dc(destinationnumber) by sourcenumber


I get something like

sourcenumber,count,dc(destinationnumber)
+15551234567,10,8

indicating it called 10 times to 8 different numbers.
adsf
perfect.

But with this:

...
| sistats count dc(destinationnumber) by sourcenumber

 

i get:

psrsvd_ct_destinationnumber,psrsvd_gc,psrsvd_v, psrsvd_vm_destinationnumber
10,10,1,+19991234567;2,+18881234567;2,+17771234567;1,+15551234567;1 (etc)

Found no clear help in the sistats page and other posts like this one it seems to work (though older posts and not using count)

Best guess is that vm column 'preserves' the details, but idk why dc() isn't working like I expect.

Labels (1)
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...