Hi all, I am new at Splunk and trying to evaluate this query.
I have some accounts, dates(week starting) and number of browsers used by the account for that date.
I have grouped the dates and number_of_browsers. there is 1 account but multiple dates and multiple or single values for browser_types. My query:
index="a" source type="ab"| rename Week Starting AS Date | stats sum(browser_ types) AS New_BrowserTypes by AccountID TotalUsers Date | eval New_BrowserTypes= round(New_BrowserTypes/TotalUsers,2) | stats MAX(New_BrowserTypes) as logins by AccountID Date | stats values(Date) values(logins) by AccountID
which gives an output something like this:
AccountID
values(date)
values(logins)
502
2020-07-20
20.00
102
2020-07-20
15.00
2020-08-25
18.00
304
2020-07-20
24.00
2020-08-25
18.00
2021-07-20
25.00
2021-08-25
15.00
For the final result, I want to use AccountID's where values(logins) are >1. So I want to use only those accounts where, logins are 2 or more. how do I achieve this? thank you in advance. Please not this is only an example, my actual AccountID's are more than 500.
... View more