Hi Anyone can help me, I am trying to get the Total count of a certain value(usernames) and disregarding its duplicate log for the day.

I am using the Singlestat panel, and currently my log sources come from a Graylog (parsed OpenVPN logs), now the logs get to “log” the username and ip every hour as this is the behaviour of the VPN server, for example:

06/08/2020 9:30:AM user1
06/08/2020 9:30 AM user2
06/08/2020 10:30:AM user1
06/08/2020 10:30 AM user2

The singlestat panel, returns me a total of 4 counts(whereas I only want the the total unique counts, so should be only 2), however been trying to use the unique count but no to avail.

Appreciate your help thanks!

I would supply some more information, such as your current actual query, and what is the datasource? Is Graylog the actual datasource within Grafana or is that just the source and the datasource is something else like Elasticsearch or whatever?

yes, elasticsearch was the datasource.

my query is just simple, just calling the username:* AND src_ip:* then everything are done via the panel itself.

