so apparently Splunk will not execute nested functions.
example | stats count,values(src),count(values(src)),values(event_desc) by error_code | sort - count
in my search "values(src)" returns a list of IP's, so "count(values(src))" should return a integer value indicating how many entries were in "values(src)". i get a "0" value.
ok, so it dont work, not sure if it should, but it dont, so whats the workaround for this?