I have the following data. Each one has a different date entry.
DATE,ACCOUNT_NUMBER, SOLUTION, FINDING
1-1-2015,1, Replaced, WIRE
1-1-2015,2, Repaired, BOX
1-1-2015,3, Repaired, BOX
1-2-2015,1, Repaired, WIRE
1-2-2015,2, Replaced, BOX
1-3-2015,3, Replaced, BOX
I am using a subsearch to remove results where only a single result exists but it is not required.
index=data [ search index=data | stats count by ACCOUNT_NUMBER | where count>1 | fields ACCOUNT_NUMBER ]
| stats values(SOLUTION) as SOL, values(FINDING) by FND by ACCOUNT_NUMBER
I get the following result:
Account_Number, SOL, FND
1, Replaced, WIRE
Repaired, WIRE
2, Repaired, BOX
Replaced, BOX
3, Repaired, BOX
Replaced, BOX
I want to count how many times the same set of results appears.
SOL, FND, Count
Replaced, Wire, 1
Replaced, Wire
Repaired, BOX, 2
Replaced, BOX
I have tried various methods of counting the result sets but haven't been able to get it to work.
Appreciate any help that can be provided. Thank you for taking the time to respond.
... View more