<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extract multiple name value pairs from a field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-name-value-pairs-from-a-field/m-p/507969#M141981</link>
    <description>&lt;P&gt;Sure. &lt;FONT color="#000000"&gt;Just add this after the &lt;STRONG&gt;&lt;EM&gt;rex &lt;/EM&gt;&lt;/STRONG&gt;command&lt;/FONT&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|eval EVENTS=mvfilter(!match(EVENTS,"normal"))&lt;/LI-CODE&gt;</description>
    <pubDate>Wed, 08 Jul 2020 04:26:37 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2020-07-08T04:26:37Z</dc:date>
    <item>
      <title>Extract multiple name value pairs from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-name-value-pairs-from-a-field/m-p/507741#M141937</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a field that contains the string below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;a) There can be fewer/more than the 4 events listed below.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;b) Value of the events will be different.&lt;/P&gt;&lt;P&gt;(event=aa)(event=bb)(event=cc)(event=normal)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;=====================================================&lt;/P&gt;&lt;P&gt;1) How can I create a new field events that equals "aa,bb,cc,normal"?&lt;/P&gt;&lt;P&gt;2) Is there a way to exclude the normal event?&amp;nbsp; So field events = "aa,bb,cc" only?&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) Is there a way to make it list like so I can filter on these events values?&amp;nbsp; (ie - potentially count # of events with aa or cc or (aa + cc)?)&amp;nbsp;&lt;/P&gt;&lt;P&gt;4) Is there a way to count the events returned in the field?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 05:34:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-name-value-pairs-from-a-field/m-p/507741#M141937</guid>
      <dc:creator>jbax</dc:creator>
      <dc:date>2020-07-07T05:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Extract multiple name value pairs from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-name-value-pairs-from-a-field/m-p/507750#M141941</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223390"&gt;@jbax&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Try regex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|rex field=events max_match=0 "event=(?&amp;lt;EVENTS&amp;gt;.+?)\)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the result, you can do rest of the stats&lt;/P&gt;&lt;P&gt;Sample data&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|makeresults|eval events="(event=aa)(event=bb)(event=cc)(event=normal) (event=xx)(event=yy)(event=zz)(event=normal)"|makemv events|mvexpand events|streamstats count as uniqueField
|rex field=events max_match=0 "event=(?&amp;lt;EVENTS&amp;gt;.+?)\)"
|eval Total=mvcount(EVENTS)
|stats count as event_count,max(Total) as Total by EVENTS,uniqueField&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let's know your final output format. We can fine tune w.r.t count and total&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 06:11:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-name-value-pairs-from-a-field/m-p/507750#M141941</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-07-07T06:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: Extract multiple name value pairs from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-name-value-pairs-from-a-field/m-p/507964#M141977</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/136781"&gt;@renjith_nair&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, this worked well for me!&amp;nbsp; &amp;nbsp;Would you know of a way to exclude values (ie - normal)?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2020 04:09:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-name-value-pairs-from-a-field/m-p/507964#M141977</guid>
      <dc:creator>jbax</dc:creator>
      <dc:date>2020-07-08T04:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: Extract multiple name value pairs from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-name-value-pairs-from-a-field/m-p/507969#M141981</link>
      <description>&lt;P&gt;Sure. &lt;FONT color="#000000"&gt;Just add this after the &lt;STRONG&gt;&lt;EM&gt;rex &lt;/EM&gt;&lt;/STRONG&gt;command&lt;/FONT&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|eval EVENTS=mvfilter(!match(EVENTS,"normal"))&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 08 Jul 2020 04:26:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-multiple-name-value-pairs-from-a-field/m-p/507969#M141981</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2020-07-08T04:26:37Z</dc:date>
    </item>
  </channel>
</rss>

