Splunk Search

splunk stats group and count by fields

Ameenulla
Engager

need query to remove duplicates from count stats

Sample input

event  email

abc      xyz@email.com

abc    xyz@email.com

abc. test@email.com

abc. test@email.com

xyz xyz@email.com

Expected output 

eventcount
abc2
xyz1

what I am getting 

eventcount
abc4
xyz1
Labels (2)
0 Karma
1 Solution

yuanliu
SplunkTrust
SplunkTrust

It is good that you try to illustrate input and desired output.  But you forget to tell us what you are trying to count that should either be 4 or 2?  In other words, you need to explain the logic between input and desired output fully and explicitly.

If I take a wild mind reading, you want to count unique number of E-mails related to each type of event.  You want to use distinctcount or dc, not count.

 

| stats dc(email) as count by event

 

Here's an emulation of your mock input

 

| makeresults format=csv data="_raw
abc      xyz@email.com
abc    xyz@email.com
abc. test@email.com
abc. test@email.com
xyz xyz@email.com"
| rex "(?<event>\w+)\W+(?<email>\S+)"
``` data emulation above ```

 

The output is

eventcount
abc2
xyz1

View solution in original post

0 Karma

yuanliu
SplunkTrust
SplunkTrust

It is good that you try to illustrate input and desired output.  But you forget to tell us what you are trying to count that should either be 4 or 2?  In other words, you need to explain the logic between input and desired output fully and explicitly.

If I take a wild mind reading, you want to count unique number of E-mails related to each type of event.  You want to use distinctcount or dc, not count.

 

| stats dc(email) as count by event

 

Here's an emulation of your mock input

 

| makeresults format=csv data="_raw
abc      xyz@email.com
abc    xyz@email.com
abc. test@email.com
abc. test@email.com
xyz xyz@email.com"
| rex "(?<event>\w+)\W+(?<email>\S+)"
``` data emulation above ```

 

The output is

eventcount
abc2
xyz1
0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...