I added sort by uid, and it did. It still shows the uid just as part of the big event record. What would be nice would be if I could pull it out to the side, so the recipient of the report could quickly see that uid 12345 had 5 events, and uid 67890 had 9 events, rather than just the detail event records. In other words (mocked up output): uid 12345 total number of events: 5 event detail1 event detail2 event detail3 etc. uid 67890 total number of events: 9 event detail1 event detail2 event detail3 etc. Also, in case you couldn't tell, I am a beginner at Splunk. Thank you for your help.
... View more