Splunk Search

splunk stats group and count by fields

Ameenulla
Engager

need query to remove duplicates from count stats

Sample input

event  email

abc      xyz@email.com

abc    xyz@email.com

abc. test@email.com

abc. test@email.com

xyz xyz@email.com

Expected output 

eventcount
abc2
xyz1

what I am getting 

eventcount
abc4
xyz1
Labels (2)
0 Karma
1 Solution

yuanliu
SplunkTrust
SplunkTrust

It is good that you try to illustrate input and desired output.  But you forget to tell us what you are trying to count that should either be 4 or 2?  In other words, you need to explain the logic between input and desired output fully and explicitly.

If I take a wild mind reading, you want to count unique number of E-mails related to each type of event.  You want to use distinctcount or dc, not count.

 

| stats dc(email) as count by event

 

Here's an emulation of your mock input

 

| makeresults format=csv data="_raw
abc      xyz@email.com
abc    xyz@email.com
abc. test@email.com
abc. test@email.com
xyz xyz@email.com"
| rex "(?<event>\w+)\W+(?<email>\S+)"
``` data emulation above ```

 

The output is

eventcount
abc2
xyz1

View solution in original post

0 Karma

yuanliu
SplunkTrust
SplunkTrust

It is good that you try to illustrate input and desired output.  But you forget to tell us what you are trying to count that should either be 4 or 2?  In other words, you need to explain the logic between input and desired output fully and explicitly.

If I take a wild mind reading, you want to count unique number of E-mails related to each type of event.  You want to use distinctcount or dc, not count.

 

| stats dc(email) as count by event

 

Here's an emulation of your mock input

 

| makeresults format=csv data="_raw
abc      xyz@email.com
abc    xyz@email.com
abc. test@email.com
abc. test@email.com
xyz xyz@email.com"
| rex "(?<event>\w+)\W+(?<email>\S+)"
``` data emulation above ```

 

The output is

eventcount
abc2
xyz1
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...