Hi. I'm quite newbie in Splunk, but I'm trying to find solution to my problem. index=zt2 (first_search) OR (second_search)
|eval xxx=if(searchmatch("first_search"), 1, 0)
|eval yyy=if(searchmatch("secont_search"), 1, 0)
|stats count(eval(xxx=1)) as "XXX",
count(eval(yyy=1)) as "YYY" I would like to count unique USER_ID per each eval expression, but problem is sometimes this same USER_ID appears in both searches (first_search and second_search), and dedup doesn't work correctly. How do I make dedup affect xxx and yyy separately in eval?
... View more