count

The count function returns the number of rows within a group. It is often used with match to get counts for specific groups in the data.

Syntax Param data types Return type
count(expression) STRING NUMBER

Code Sample

  • Return the count of successful user logins over time.

    metadata.event_type = "USER_LOGIN"
    $security_result = security_result.action
    $security_result = "ALLOW"
    $date = timestamp.get_date(metadata.event_timestamp.seconds, "America/Los_Angeles")
    match:
        $security_result, $date
    outcome:
        $event_count = count(metadata.id)