Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Count combination of Multivalue Field

$
0
0
Hi, I wonder whether someone can help me please. I'm using the query below to extract the different actions performed for each submission by detail.Id `submissions_wmf(Submission)` detail.isManualChange=true NOT ( detail.changeType=ChangeBank OR detail.changeType=ChangeBIK OR detail.changeType=ChangeOtherIncome OR detail.changeType=ChangeSocialSecurityBenefit OR detail.changeType=HaveBenefitsEnded OR detail.changeType=HavePartnerBenefitsEnded) | stats count list(detail.changeType) as ChangeType by detail.id | table ChangeType count The query works find and extracts data as per the attachment[1] But I'd like to extend this by adding another total which counts the number of times the combination of values in the ChangeType Column exist. So using the attachment as an example. Where Change A and Change B exist together this would be a count of **2**. I've looked at streamstats and evenstats and also changed the values to a string and count this, but I can't pull both totals together on the same table. I just wondered whether someone could look at this please and offer some guidance on how I may go about this. Many thanks and kind regards Chris [1]: /storage/temp/216806-changetype.png

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>