<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search multi-valued field with specific values in sequence in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Search-multi-valued-field-with-specific-values-in-sequence/m-p/570700#M10143</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226708"&gt;@vjajula&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;YOUR_SEARCH | mvexpand ColY
| autoregress ColY as p_ColY p=1 | autoregress ColX as p_ColX p=1
| eval cnt = if(p_ColY!=ColY and ColX=p_ColX,1,0)
| stats list(ColY) as ColY sum(cnt) as cnt by ColX
| where cnt &amp;gt; 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Sample Search :&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval _raw="ColX    ColY
A123456 ON,ON,ON
A123457 ON,OFF,ON,OFF
A123458 ON,ON,OFF,ON,ON,ON,OFF
A123459 OFF,OFF,OFF
A123460 ON,ON,ON,OFF,OFF,OFF" | multikv forceheader=1
| eval ColY=split(ColY,",")
| mvexpand ColY
| autoregress ColY as p_ColY p=1 | autoregress ColX as p_ColX p=1
| eval cnt = if(p_ColY!=ColY and ColX=p_ColX,1,0)
| stats list(ColY) as ColY sum(cnt) as cnt by ColX
| where cnt &amp;gt; 0&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;Output.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-10-13 at 10.13.42 AM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16382i06353D5381809CB6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2021-10-13 at 10.13.42 AM.png" alt="Screenshot 2021-10-13 at 10.13.42 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一 &amp;nbsp; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated. &lt;/P&gt;</description>
    <pubDate>Wed, 13 Oct 2021 04:43:57 GMT</pubDate>
    <dc:creator>kamlesh_vaghela</dc:creator>
    <dc:date>2021-10-13T04:43:57Z</dc:date>
    <item>
      <title>Search multi-valued field with specific values in sequence</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Search-multi-valued-field-with-specific-values-in-sequence/m-p/570695#M10142</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have another request similar to my previous post but with a variation&lt;/P&gt;&lt;P&gt;Here is the multi-valued field ColY. ColY has only two values ON or OFF. I need to find all rows which changed values from ON to OFF or vice-versa in any order. Below is the example&lt;/P&gt;&lt;TABLE width="340"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="187"&gt;ColX&lt;/TD&gt;&lt;TD width="153"&gt;ColY&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A123456&lt;/TD&gt;&lt;TD width="153"&gt;ON&lt;BR /&gt;ON&lt;BR /&gt;ON&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A123457&lt;/TD&gt;&lt;TD width="153"&gt;ON&lt;BR /&gt;OFF&lt;BR /&gt;ON&lt;BR /&gt;OFF&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A123458&lt;/TD&gt;&lt;TD width="153"&gt;ON&lt;BR /&gt;ON&lt;BR /&gt;OFF&lt;BR /&gt;ON&lt;BR /&gt;ON&lt;BR /&gt;ON&lt;BR /&gt;OFF&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A123459&lt;/TD&gt;&lt;TD width="153"&gt;OFF&lt;BR /&gt;OFF&lt;BR /&gt;OFF&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A123460&lt;/TD&gt;&lt;TD width="153"&gt;ON&lt;BR /&gt;ON&lt;BR /&gt;ON&lt;BR /&gt;OFF&lt;BR /&gt;OFF&lt;BR /&gt;OFF&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Required output&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;TABLE width="427"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="187"&gt;ColX&lt;/TD&gt;&lt;TD width="153"&gt;ColY&lt;/TD&gt;&lt;TD width="87"&gt;totalChanges&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A123457&lt;/TD&gt;&lt;TD width="153"&gt;ON&lt;BR /&gt;OFF&lt;BR /&gt;ON&lt;BR /&gt;OFF&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A123458&lt;/TD&gt;&lt;TD width="153"&gt;ON&lt;BR /&gt;ON&lt;BR /&gt;OFF&lt;BR /&gt;ON&lt;BR /&gt;ON&lt;BR /&gt;ON&lt;BR /&gt;OFF&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A123460&lt;/TD&gt;&lt;TD width="153"&gt;ON&lt;BR /&gt;ON&lt;BR /&gt;ON&lt;BR /&gt;OFF&lt;BR /&gt;OFF&lt;BR /&gt;OFF&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 13 Oct 2021 01:48:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Search-multi-valued-field-with-specific-values-in-sequence/m-p/570695#M10142</guid>
      <dc:creator>vjajula</dc:creator>
      <dc:date>2021-10-13T01:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: Search multi-valued field with specific values in sequence</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Search-multi-valued-field-with-specific-values-in-sequence/m-p/570700#M10143</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226708"&gt;@vjajula&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;YOUR_SEARCH | mvexpand ColY
| autoregress ColY as p_ColY p=1 | autoregress ColX as p_ColX p=1
| eval cnt = if(p_ColY!=ColY and ColX=p_ColX,1,0)
| stats list(ColY) as ColY sum(cnt) as cnt by ColX
| where cnt &amp;gt; 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Sample Search :&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval _raw="ColX    ColY
A123456 ON,ON,ON
A123457 ON,OFF,ON,OFF
A123458 ON,ON,OFF,ON,ON,ON,OFF
A123459 OFF,OFF,OFF
A123460 ON,ON,ON,OFF,OFF,OFF" | multikv forceheader=1
| eval ColY=split(ColY,",")
| mvexpand ColY
| autoregress ColY as p_ColY p=1 | autoregress ColX as p_ColX p=1
| eval cnt = if(p_ColY!=ColY and ColX=p_ColX,1,0)
| stats list(ColY) as ColY sum(cnt) as cnt by ColX
| where cnt &amp;gt; 0&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;Output.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-10-13 at 10.13.42 AM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16382i06353D5381809CB6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2021-10-13 at 10.13.42 AM.png" alt="Screenshot 2021-10-13 at 10.13.42 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一 &amp;nbsp; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated. &lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 04:43:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Search-multi-valued-field-with-specific-values-in-sequence/m-p/570700#M10143</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-10-13T04:43:57Z</dc:date>
    </item>
  </channel>
</rss>

