Hello @jt_splunk
The statement: | where count > 4 | sort value desc
does not work for me:(
Does where word is not deprecated?
And why do You dedup by date_wday hostanem and name
instead only by date_wday
"If I understand correctly, for each day of the week, you only care if an event is present or not" -- correct
"Then, you want to know if that event occurs over the course of 5 days, right?" -- Then I want to know if that event occurs 5 times or more in the week (e.g. Monday, Tuesday, Wednesday, Friday and Sunday: 5 times in the week)
(e.g.2 Monday, Tuesday, Wednesday, Thursday, Friday and Sunday: 6 times in the week
Best Regards,
C4r7m4n
... View more