<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to remove event/(s) from the values(Data) field? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551407#M156483</link>
    <description>&lt;P&gt;OK, so now it's clearer.&amp;nbsp; You have 3 records, and each of these has at least Data containing AreaOIC and these cover different data counts and different dates.&lt;/P&gt;&lt;P&gt;So, which of these 3 rows should be included or excluded in the total created by the final stats statement.&lt;/P&gt;&lt;P&gt;Note that Datacount is coming from all 4 Data values across your results,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;AreaOIC&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Biodiversity2&lt;BR /&gt;Land_Ownership&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PlanningCommitment&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;so what exactly do you want to show in your final result from that stats of those 3 rows?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 May 2021 22:48:12 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2021-05-12T22:48:12Z</dc:date>
    <item>
      <title>How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551150#M156390</link>
      <description>&lt;P&gt;Hi I would like to remove some Data from my search (only want AreaOIC), however, I tried to do Data = AreaOIC or Data != XXXXX (*xxxx = field I would like to exclude), it still include other events where I do not want. How should I go about doing this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;| tstats values(Arcgis.email) as email, values(Arcgis.agency) as Agency, values(Arcgis.mapservice) as Data, count(Arcgis.mapservice) as Datacount, values(Arcgis.mapfolder) as Mapfolder from datamodel=Arcgis where (host=URASVR334) groupby _time Arcgis.email | search [tstats values(Eplanner.loginname) as email from datamodel=Eplanner | table email] NOT Mapfolder=*ONETOOL* NOT Mapfolder=*GEMMA* NOT Mapfolder=*Scenarios* NOT Mapfolder=*USDashboard* NOT Mapfolder=*EPAC* NOT Mapfolder=*CLI* NOT Mapfolder=*MP14* NOT Data=*_3414* | eval Email=upper(email) | append [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.layers) as Data, count(Eplanner.layers) as Datacount from datamodel=Eplanner groupby _time Eplanner.email | eval Email=upper(Email)] | append [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.typename) as Data, count(Eplanner.typename) as Datacount from datamodel=Eplanner groupby _time Eplanner.email | eval Email=upper(Email)] | lookup eplannerusers.csv "Login Name" as Email OUTPUT "Login Name" Date Group as Group as Group Department Designation "Full Name" as Fullname | strcat Fullname " / " Department Name_Dept&lt;/P&gt;&lt;P&gt;| search Agency=PotatoEdu Email=&lt;A href="mailto:Potatohero@potato.edu.SG" target="_blank" rel="noopener"&gt;Potatohero@potato.edu.SG&amp;nbsp;Group = PotatoEdu Data = AreaOIC&lt;BR /&gt;&lt;BR /&gt;| stats values(Fullname), values(Designation), values(Name_Dept), values(Group), values(Department), values(Agency), values(Mapfolder), values(Data), sum(Datacount) by Email&lt;/A&gt;&lt;/P&gt;&lt;DIV class="shared-page"&gt;&lt;DIV class="main-section-body"&gt;&lt;DIV class="search"&gt;&lt;DIV class="search-results"&gt;&lt;DIV class="tab-content"&gt;&lt;DIV class="tab-pane search-results-statisticspane"&gt;&lt;DIV class="shared-reportvisualizer"&gt;&lt;DIV class="viz-controller"&gt;&lt;DIV class="facets-container"&gt;&lt;DIV class="viz-panel  viz-facet-size-medium"&gt;&lt;DIV class="lazy-view-container lazy-results-table shared-resultstable-lazyresultstable"&gt;&lt;DIV class="shared-resultstabledrilldown results-table"&gt;&lt;BR /&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Email&lt;/TD&gt;&lt;TD&gt;values(Fullname)&lt;/TD&gt;&lt;TD&gt;values(Designation)&lt;/TD&gt;&lt;TD&gt;values(Name_Dept)&lt;/TD&gt;&lt;TD&gt;values(Group)&lt;/TD&gt;&lt;TD&gt;values(Department)&lt;/TD&gt;&lt;TD&gt;values(Agency)&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;values(Mapfolder)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;values(Data)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;sum(Datacount)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="212px" height="135px"&gt;Potatohero@potato.edu.SG&lt;/TD&gt;&lt;TD width="40px" height="135px"&gt;Ken Do&lt;/TD&gt;&lt;TD width="67px" height="135px"&gt;Programmer&lt;/TD&gt;&lt;TD width="55px" height="135px"&gt;Ken Do&lt;/TD&gt;&lt;TD width="73px" height="135px"&gt;IT&lt;/TD&gt;&lt;TD width="40px" height="135px"&gt;IT&amp;nbsp;&lt;/TD&gt;&lt;TD width="43px" height="135px"&gt;PotatoEDU&lt;/TD&gt;&lt;TD width="100px" height="135px"&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;Boundaries&lt;DIV class="multivalue-subcell"&gt;DevtControl&lt;DIV class="multivalue-subcell"&gt;Planning&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="168px" height="135px"&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;AreaOIC&lt;DIV class="multivalue-subcell"&gt;Land_Ownership&lt;DIV class="multivalue-subcell"&gt;PlanningCommitment&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="40px" height="135px"&gt;52&lt;DIV class="shared-page"&gt;&lt;DIV class="main-section-body"&gt;&lt;DIV class="search"&gt;&lt;DIV class="search-results"&gt;&lt;DIV class="tab-content"&gt;&lt;DIV class="tab-pane search-results-statisticspane"&gt;&lt;DIV class="search-results-statisticspane-statisticscontrols"&gt;&lt;DIV class="statistics-controls-inner"&gt;&lt;DIV class="btn-group pull-left shared-controls-syntheticselectcontrol control-default"&gt;&lt;DIV class="dropdown-menu dropdown-menu-selectable dropdown-menu-default  dropdown-menu-narrow "&gt;&lt;DIV class="arrow"&gt;&amp;nbsp;&lt;DIV class="shared-reportvisualizer"&gt;&lt;DIV class="viz-controller"&gt;&lt;DIV class="facets-container"&gt;&lt;DIV class="viz-panel  viz-facet-size-medium"&gt;&lt;DIV class="lazy-view-container lazy-results-table shared-resultstable-lazyresultstable"&gt;&lt;DIV class="shared-resultstabledrilldown results-table"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 11 May 2021 03:22:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551150#M156390</guid>
      <dc:creator>PotatoHero</dc:creator>
      <dc:date>2021-05-11T03:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551155#M156395</link>
      <description>&lt;P&gt;Your values(Data) fields shows that the text 'AreaOIC' is either part of a longer string or one of multiple values of that field.&lt;/P&gt;&lt;P&gt;If it is a part of a longer string, then wrap it with wildcard characters. If it one of multiple values, then use the syntax&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where !isnull(mvfind(Data, "AreaOIC"))&lt;/LI-CODE&gt;&lt;P&gt;after your final search command.&lt;/P&gt;&lt;P&gt;TIP: When doing stats values(Data), use a field renaming command also, so you end up with a useful field name after the stats, i.e.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats values(Data) as Data&lt;/LI-CODE&gt;&lt;P&gt;as is done in your main search body.&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 04:21:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551155#M156395</guid>
      <dc:creator>abowesman</dc:creator>
      <dc:date>2021-05-11T04:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551177#M156412</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/188274"&gt;@abowesman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply, I have tried:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where !isnull(mvfind(Data, "AreaOIC"))&lt;/LI-CODE&gt;&lt;P&gt;however, it doesn't work, it still shows the same result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May I know how do I do "&lt;SPAN&gt;wrap it with wildcard characters."?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 06:44:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551177#M156412</guid>
      <dc:creator>PotatoHero</dc:creator>
      <dc:date>2021-05-11T06:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551297#M156442</link>
      <description>&lt;P&gt;Wrap with wildcard characters means replace your current statement, which does&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search .... Data = AreaOIC&lt;/LI-CODE&gt;&lt;P&gt;with&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search .... Data = "*AreaOIC*"&lt;/LI-CODE&gt;&lt;P&gt;Where did you place the mvfind() statement. Did you place it before the stats and if so, can you can an example of the data it found that it should have not found&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 00:56:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551297#M156442</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-05-12T00:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551299#M156443</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ah thanks for explaining. I have tried the wrapping before and it doesn't work.&lt;/P&gt;&lt;P&gt;I have tried putting the statement "| where !isnull(mvfind(Data, "AreaOIC"))" in 3 different places to try it out but none worked:&lt;/P&gt;&lt;P&gt;1. before search statement&lt;/P&gt;&lt;P&gt;2. before stats statement&lt;/P&gt;&lt;P&gt;3. after stats statement&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 01:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551299#M156443</guid>
      <dc:creator>PotatoHero</dc:creator>
      <dc:date>2021-05-12T01:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551302#M156446</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234287"&gt;@PotatoHero&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you post some examples, which show the query and the results. It's hard to diagnose the issue without being able to see what you are or are not getting.&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 02:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551302#M156446</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-05-12T02:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551304#M156447</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;1.&lt;BR /&gt;| tstats values(Arcgis.email) as email, values(Arcgis.agency) as Agency, values(Arcgis.mapservice) as Data, count(Arcgis.mapservice) as Datacount, values(Arcgis.mapfolder) as Mapfolder from datamodel=Arcgis where (host=URASVR334) groupby _time Arcgis.email | search [tstats values(Eplanner.loginname) as email from datamodel=Eplanner | table email] NOT Mapfolder=*ONETOOL* NOT Mapfolder=*GEMMA* NOT Mapfolder=*Scenarios* NOT Mapfolder=*USDashboard* NOT Mapfolder=*EPAC* NOT Mapfolder=*CLI* NOT Mapfolder=*MP14* NOT Data=*_3414* | eval Email=upper(email) | append [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.layers) as Data, count(Eplanner.layers) as Datacount from datamodel=Eplanner groupby _time Eplanner.email | eval Email=upper(Email)] | append [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.typename) as Data, count(Eplanner.typename) as Datacount from datamodel=Eplanner groupby _time Eplanner.email | eval Email=upper(Email)] | lookup eplannerusers.csv "Login Name" as Email OUTPUT "Login Name" Date Group as Group Department Designation "Full Name" as Fullname | strcat Fullname " / " Department Name_Dept| search Agency=URA Email=TAN@potato.hero.sg Data=AreaOIC&lt;BR /&gt;| stats values(Fullname), values(Designation), values(Name_Dept), values(Group), values(Department), values(Agency), values(Mapfolder), values(Data), sum(Datacount) by Email&lt;BR /&gt;| where !isnull(mvfind(Data, "AreaOIC"))&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;RESULTS:&lt;/STRONG&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class="shared-page"&gt;&lt;DIV class="main-section-body"&gt;&lt;DIV class="search"&gt;&lt;DIV class="search-results"&gt;&lt;DIV class="tab-content"&gt;&lt;DIV class="tab-pane search-results-statisticspane"&gt;&lt;DIV class="message-single search-results-shared-jobdispatchstatemessage"&gt;&lt;DIV class="alert alert-error"&gt;No results found.&lt;DIV class="alert alert-error"&gt;&amp;nbsp;&lt;DIV class="alert alert-error"&gt;&amp;nbsp;&lt;DIV class="alert alert-error"&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;STRONG&gt;2.&lt;BR /&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;P&gt;| tstats values(Arcgis.email) as email, values(Arcgis.agency) as Agency, values(Arcgis.mapservice) as Data, count(Arcgis.mapservice) as Datacount, values(Arcgis.mapfolder) as Mapfolder from datamodel=Arcgis where (host=URASVR334) groupby _time Arcgis.email | search [tstats values(Eplanner.loginname) as email from datamodel=Eplanner | table email] NOT Mapfolder=*ONETOOL* NOT Mapfolder=*GEMMA* NOT Mapfolder=*Scenarios* NOT Mapfolder=*USDashboard* NOT Mapfolder=*EPAC* NOT Mapfolder=*CLI* NOT Mapfolder=*MP14* NOT Data=*_3414* | eval Email=upper(email) | append [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.layers) as Data, count(Eplanner.layers) as Datacount from datamodel=Eplanner groupby _time Eplanner.email | eval Email=upper(Email)] | append [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.typename) as Data, count(Eplanner.typename) as Datacount from datamodel=Eplanner groupby _time Eplanner.email | eval Email=upper(Email)] | lookup eplannerusers.csv "Login Name" as Email OUTPUT "Login Name" Date Group as Group Department Designation "Full Name" as Fullname | strcat Fullname " / " Department Name_Dept&lt;/P&gt;&lt;P&gt;| search Agency=&lt;SPAN&gt;Potato Hero Email=&lt;SPAN&gt;TAN@potato.hero.sg Data=AreaOIC&lt;BR /&gt;| where !isnull(mvfind(Data, "AreaOIC"))&lt;BR /&gt;| stats values(Fullname), values(Designation), values(Name_Dept), values(Group), values(Department), values(Agency), values(Mapfolder), values(Data), sum(Datacount) by Email&lt;BR /&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;RESULTS:&lt;/STRONG&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="alert alert-error"&gt;&amp;nbsp; &lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="10%" height="25px"&gt;Email&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Fullname)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Designation)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Name_Dept)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Group)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Department)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Agency)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Mapfolder)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Data)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;sum(Datacount)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="95px"&gt;&lt;SPAN&gt;TAN@potato.hero.sg&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;Tan Potato&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;IT Analyst&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;Tan Potato_IT&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;ITA&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;IT&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;&lt;SPAN&gt;Potato Hero&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;Boundaries&lt;BR /&gt;DevtControl&lt;BR /&gt;Planning&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;AreaOIC&lt;BR /&gt;Biodiversity2&lt;BR /&gt;Land_Ownership&lt;BR /&gt;PlanningCommitment&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;236&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;3.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;| tstats values(Arcgis.email) as email, values(Arcgis.agency) as Agency, values(Arcgis.mapservice) as Data, count(Arcgis.mapservice) as Datacount, values(Arcgis.mapfolder) as Mapfolder from datamodel=Arcgis where (host=URASVR334) groupby _time Arcgis.email | search [tstats values(Eplanner.loginname) as email from datamodel=Eplanner | table email] NOT Mapfolder=*ONETOOL* NOT Mapfolder=*GEMMA* NOT Mapfolder=*Scenarios* NOT Mapfolder=*USDashboard* NOT Mapfolder=*EPAC* NOT Mapfolder=*CLI* NOT Mapfolder=*MP14* NOT Data=*_3414* | eval Email=upper(email) | append [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.layers) as Data, count(Eplanner.layers) as Datacount from datamodel=Eplanner groupby _time Eplanner.email | eval Email=upper(Email)] | append [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.typename) as Data, count(Eplanner.typename) as Datacount from datamodel=Eplanner groupby _time Eplanner.email | eval Email=upper(Email)] | lookup eplannerusers.csv "Login Name" as Email OUTPUT "Login Name" Date Group as Group Department Designation "Full Name" as Fullname | strcat Fullname " / " Department Name_Dept&lt;/P&gt;&lt;P&gt;| where !isnull(mvfind(Data, "AreaOIC"))&lt;BR /&gt;| search Agency=URA Email=Jamie_TAN@ura.gov.sg Data=AreaOIC&lt;BR /&gt;| stats values(Fullname), values(Designation), values(Name_Dept), values(Group), values(Department), values(Agency), values(Mapfolder), values(Data), sum(Datacount) by Email&lt;BR /&gt;&lt;BR /&gt;RESULTS:&lt;BR /&gt;Same as 2.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/188274"&gt;@abowesman&lt;/a&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 02:51:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551304#M156447</guid>
      <dc:creator>PotatoHero</dc:creator>
      <dc:date>2021-05-12T02:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551306#M156448</link>
      <description>&lt;P&gt;Result 1 is correct, because you do not have a field called Data. I mentioned that you should rename the values(Data) as Data in your stats, otherwise you no longer have a field called data.&lt;/P&gt;&lt;P&gt;Result 2 is showing you a result where the Data field contains AreaOIC - is that wrong? You only are showing a single result row - if it is wrong, then what result are you expecting?&lt;/P&gt;&lt;P&gt;Result 3 same reply as for 2.&lt;/P&gt;&lt;P&gt;When you originally said you want to remove events, can you explain what events are present that should not be.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 04:31:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551306#M156448</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-05-12T04:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551310#M156449</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi thanks for your prompt reply, maybe my understanding of events might be wrong. Okay this is the result that I want to get...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FROM:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="10%" height="25px"&gt;Email&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Fullname)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Designation)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Name_Dept)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Group)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Department)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Agency)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Mapfolder)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;&lt;FONT color="#FF0000"&gt;values(Data)&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;sum(Datacount)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="95px"&gt;&lt;SPAN&gt;TAN@potato.hero.sg&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;Tan Potato&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;IT Analyst&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;Tan Potato_IT&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;ITA&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;IT&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;&lt;SPAN&gt;Potato Hero&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;Boundaries&lt;BR /&gt;DevtControl&lt;BR /&gt;Planning&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;&lt;FONT color="#FF0000"&gt;AreaOIC&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Biodiversity2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Land_Ownership&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;PlanningCommitment&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;236&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TO:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="10%" height="25px"&gt;Email&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Fullname)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Designation)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Name_Dept)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Group)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Department)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Agency)&lt;/TD&gt;&lt;TD width="10%" height="25px"&gt;values(Mapfolder)&lt;/TD&gt;&lt;TD width="7.364568081991215%" height="25px"&gt;&lt;FONT color="#FF0000"&gt;values(Data)&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="12.635431918008784%" height="25px"&gt;sum(Datacount)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="95px"&gt;&lt;SPAN&gt;TAN@potato.hero.sg&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;Tan Potato&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;IT Analyst&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;Tan Potato_IT&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;ITA&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;IT&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;&lt;SPAN&gt;Potato Hero&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="10%" height="95px"&gt;Boundaries&lt;BR /&gt;DevtControl&lt;BR /&gt;Planning&lt;/TD&gt;&lt;TD width="7.364568081991215%" height="95px"&gt;&lt;FONT color="#FF0000"&gt;AreaOIC&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD width="12.635431918008784%" height="95px"&gt;236&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do look at the values in &lt;FONT color="#FF0000"&gt;Red&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 04:36:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551310#M156449</guid>
      <dc:creator>PotatoHero</dc:creator>
      <dc:date>2021-05-12T04:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551317#M156450</link>
      <description>&lt;P&gt;OK, so this is your search so far... (please use the code sample option to paste in your search code &amp;lt;/&amp;gt;)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats values(Arcgis.email) as email, values(Arcgis.agency) as Agency, values(Arcgis.mapservice) as Data, count(Arcgis.mapservice) as Datacount, values(Arcgis.mapfolder) as Mapfolder from datamodel=Arcgis where (host=URASVR334) groupby _time Arcgis.email 
| search 
    [ tstats values(Eplanner.loginname) as email from datamodel=Eplanner 
    | table email] NOT Mapfolder=*ONETOOL* NOT Mapfolder=*GEMMA* NOT Mapfolder=*Scenarios* NOT Mapfolder=*USDashboard* NOT Mapfolder=*EPAC* NOT Mapfolder=*CLI* NOT Mapfolder=*MP14* NOT Data=*_3414* 
| eval Email=upper(email) 
| append 
    [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.layers) as Data, count(Eplanner.layers) as Datacount from datamodel=Eplanner groupby _time Eplanner.email 
    | eval Email=upper(Email)] 
| append 
    [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.typename) as Data, count(Eplanner.typename) as Datacount from datamodel=Eplanner groupby _time Eplanner.email 
    | eval Email=upper(Email)] 
| lookup eplannerusers.csv "Login Name" as Email OUTPUT "Login Name" Date Group as Group Department Designation "Full Name" as Fullname 
| strcat Fullname " / " Department Name_Dept 
| search Agency=Potato Hero Email=TAN@potato.hero.sg Data=AreaOIC 
| where !isnull(mvfind(Data, "AreaOIC")) 
| stats values(Fullname), values(Designation), values(Name_Dept), values(Group), values(Department), values(Agency), values(Mapfolder), values(Data), sum(Datacount) by Email&lt;/LI-CODE&gt;&lt;P&gt;You Data field comes from&amp;nbsp;&lt;/P&gt;&lt;P&gt;First line of search =&amp;nbsp;values(Arcgis.mapservice) as Data&lt;/P&gt;&lt;P&gt;First append line =&amp;nbsp;values(Eplanner.layers) as Data&lt;/P&gt;&lt;P&gt;Second append line =&amp;nbsp;values(Eplanner.typename) as Data&lt;/P&gt;&lt;P&gt;so, you have types of 'Data' that may appear. Consider now&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search Agency=Potato Hero Email=TAN@potato.hero.sg Data=AreaOIC&lt;/LI-CODE&gt;&lt;P&gt;This line will, in theory only include Data values that are AreaOIC&lt;/P&gt;&lt;P&gt;so if you remove all of your search after that, how many rows (events) do you end up with and what are the values of Data?&lt;/P&gt;&lt;P&gt;Note that your search command is most likely bad, in that I suspect you should really be quoting&lt;/P&gt;&lt;P&gt;Agency="Potato Hero", otherwise you are searching for Agency=Potato and then you are searching for the word Hero&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please share what results you get from the above and what the real values of Data in each event are&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 06:14:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551317#M156450</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-05-12T06:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551319#M156452</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"so if you remove all of your search after that, how many rows (events) do you end up with and what are the values of Data?" -&amp;gt; do you mean remove anything after my search statement?&amp;nbsp; (e.g. stats values(Fullname)....)&amp;nbsp; &amp;nbsp; what I get from it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 06:21:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551319#M156452</guid>
      <dc:creator>PotatoHero</dc:creator>
      <dc:date>2021-05-12T06:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551325#M156454</link>
      <description>&lt;P&gt;yes&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 07:17:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551325#M156454</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-05-12T07:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551328#M156456</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats values(Arcgis.email) as email, values(Arcgis.agency) as Agency, values(Arcgis.mapservice) as Data, count(Arcgis.mapservice) as Datacount, values(Arcgis.mapfolder) as Mapfolder from datamodel=Arcgis where (host=URASVR334) groupby _time Arcgis.email | search [tstats values(Eplanner.loginname) as email from datamodel=Eplanner | table email] NOT Mapfolder=*ONETOOL* NOT Mapfolder=*GEMMA* NOT Mapfolder=*Scenarios* NOT Mapfolder=*USDashboard* NOT Mapfolder=*EPAC* NOT Mapfolder=*CLI* NOT Mapfolder=*MP14* NOT Data=*_3414* | eval Email=upper(email) | append [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.layers) as Data, count(Eplanner.layers) as Datacount from datamodel=Eplanner groupby _time Eplanner.email | eval Email=upper(Email)] | append [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.typename) as Data, count(Eplanner.typename) as Datacount from datamodel=Eplanner groupby _time Eplanner.email | eval Email=upper(Email)] | lookup eplannerusers.csv "Login Name" as Email OUTPUT "Login Name" Date Group as Group Department Designation "Full Name" as Fullname | strcat Fullname " / " Department Name_Dept | search Agency="Potato Hero" Email=Potato@Hero.potato.sg Data="AreaOIC"​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="125.22522522522523%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="10%" height="37px"&gt;&lt;STRONG&gt;_TIME&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="10%" height="37px"&gt;&lt;STRONG&gt;Arcgis.email&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="10%" height="37px"&gt;&lt;STRONG&gt;email&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="10%" height="37px"&gt;&lt;STRONG&gt;Agency&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="10%" height="37px"&gt;&lt;STRONG&gt;Data&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="10%" height="37px"&gt;&lt;STRONG&gt;Datacount&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="10%" height="37px"&gt;&lt;STRONG&gt;Mapfolder&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="10%" height="37px"&gt;&lt;STRONG&gt;Date&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="10%" height="37px"&gt;&lt;STRONG&gt;Department&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="0.15625%" height="37px"&gt;&lt;STRONG&gt;Designation&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="0.15625%" height="37px"&gt;&lt;STRONG&gt;Email&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="0.3125%" height="37px"&gt;&lt;STRONG&gt;Eplanner.email&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="0.625%" height="37px"&gt;&lt;STRONG&gt;Fullname&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="0.819000819000819%" height="37px"&gt;&lt;STRONG&gt;Group&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="2.930999180999181%" height="37px"&gt;&lt;STRONG&gt;Login Name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="5%" height="37px"&gt;&lt;STRONG&gt;Name_Dept&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="69px"&gt;2021-04-12&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;Potato@Hero.potato.sg&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;Potato@Hero.potato.sg&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;Potato Hero&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;AreaOIC&lt;BR /&gt;Biodiversity2&lt;BR /&gt;PlanningCommitment&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;62&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;Boundaries&lt;BR /&gt;DevtControl&lt;BR /&gt;Planning&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;23/11/2020&lt;BR /&gt;23:30&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;IT&lt;/TD&gt;&lt;TD width="0.15625%" height="69px"&gt;Programmer&lt;/TD&gt;&lt;TD width="0.15625%" height="69px"&gt;&lt;SPAN&gt;Potato@Hero.potato.sg&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="0.3125%" height="69px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="0.625%" height="69px"&gt;Tan Jason&lt;/TD&gt;&lt;TD width="0.819000819000819%" height="69px"&gt;ITA&lt;/TD&gt;&lt;TD width="2.930999180999181%" height="69px"&gt;&lt;SPAN&gt;Potato@Hero.potato.sg&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="5%" height="69px"&gt;Tan Jason, ITA&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="47px"&gt;2021-04-23&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;Potato@Hero.potato.sg&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;Potato@Hero.potato.sg&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;&lt;SPAN&gt;Potato Hero&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;AreaOIC&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;122&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;Boundaries&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;23/11/2020&lt;BR /&gt;23:30&lt;/TD&gt;&lt;TD width="10%" height="47px"&gt;&lt;SPAN&gt;IT&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="0.15625%" height="47px"&gt;&lt;SPAN&gt;Programmer&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="0.15625%" height="47px"&gt;&lt;SPAN&gt;Potato@Hero.potato.sg&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="0.3125%" height="47px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="0.625%" height="47px"&gt;&lt;SPAN&gt;Tan Jason&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="0.819000819000819%" height="47px"&gt;&lt;SPAN&gt;ITA&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="2.930999180999181%" height="47px"&gt;&lt;SPAN&gt;Potato@Hero.potato.sg&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="5%" height="47px"&gt;&lt;SPAN&gt;Tan Jason, ITA&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="10%" height="69px"&gt;2021-05-04&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;Potato@Hero.potato.sg&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;Potato@Hero.potato.sg&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;&lt;SPAN&gt;Potato Hero&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;AreaOIC&lt;BR /&gt;Land_Ownership&lt;BR /&gt;PlanningCommitment&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;52&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;Boundaries&lt;BR /&gt;DevtControl&lt;BR /&gt;Planning&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;&lt;SPAN&gt;23/11/2020&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;23:30&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="10%" height="69px"&gt;&lt;SPAN&gt;IT&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="0.15625%" height="69px"&gt;&lt;SPAN&gt;Programmer&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="0.15625%" height="69px"&gt;&lt;SPAN&gt;Potato@Hero.potato.sg&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="0.3125%" height="69px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="0.625%" height="69px"&gt;&lt;SPAN&gt;Tan Jason&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="0.819000819000819%" height="69px"&gt;&lt;SPAN&gt;ITA&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="2.930999180999181%" height="69px"&gt;&lt;SPAN&gt;Potato@Hero.potato.sg&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD width="5%" height="69px"&gt;&lt;SPAN&gt;Tan Jason, ITA&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="shared-page"&gt;&lt;DIV class="main-section-body"&gt;&lt;DIV class="search"&gt;&lt;DIV class="search-results"&gt;&lt;DIV class="tab-content"&gt;&lt;DIV class="tab-pane search-results-statisticspane"&gt;&lt;DIV class="shared-reportvisualizer"&gt;&lt;DIV class="viz-controller"&gt;&lt;DIV class="facets-container"&gt;&lt;DIV class="viz-panel  viz-facet-size-medium"&gt;&lt;DIV class="lazy-view-container lazy-results-table shared-resultstable-lazyresultstable"&gt;&lt;DIV class="shared-resultstabledrilldown results-table"&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;DIV class="multivalue-subcell"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 07:52:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551328#M156456</guid>
      <dc:creator>PotatoHero</dc:creator>
      <dc:date>2021-05-12T07:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551407#M156483</link>
      <description>&lt;P&gt;OK, so now it's clearer.&amp;nbsp; You have 3 records, and each of these has at least Data containing AreaOIC and these cover different data counts and different dates.&lt;/P&gt;&lt;P&gt;So, which of these 3 rows should be included or excluded in the total created by the final stats statement.&lt;/P&gt;&lt;P&gt;Note that Datacount is coming from all 4 Data values across your results,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;AreaOIC&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Biodiversity2&lt;BR /&gt;Land_Ownership&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PlanningCommitment&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;so what exactly do you want to show in your final result from that stats of those 3 rows?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 22:48:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551407#M156483</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-05-12T22:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551425#M156487</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/6367"&gt;@bowesmana&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your prompt reply. As you can see some rows have more than 1 data of AreaOIC, Biodiversity2, Land_Ownership, and PlanningCommitment. &lt;STRONG&gt;So my goal is:&lt;BR /&gt;1. to be able to filter one and only one data per row. (e.g. AreaOIC only)&lt;BR /&gt;2. Datacount is only counting that data and not the other data&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Not sure if that is possible. Let me know if you know how ... or what the issue is...&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 07:48:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551425#M156487</guid>
      <dc:creator>PotatoHero</dc:creator>
      <dc:date>2021-05-13T07:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove event/(s) from the values(Data) field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551505#M156505</link>
      <description>&lt;P&gt;So, you need to get back to basics. This is your most recent search:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats values(Arcgis.email) as email, values(Arcgis.agency) as Agency, values(Arcgis.mapservice) as Data, count(Arcgis.mapservice) as Datacount, values(Arcgis.mapfolder) as Mapfolder from datamodel=Arcgis where (host=URASVR334) groupby _time Arcgis.email 
| search 
    [ tstats values(Eplanner.loginname) as email from datamodel=Eplanner 
    | table email] NOT Mapfolder=*ONETOOL* NOT Mapfolder=*GEMMA* NOT Mapfolder=*Scenarios* NOT Mapfolder=*USDashboard* NOT Mapfolder=*EPAC* NOT Mapfolder=*CLI* NOT Mapfolder=*MP14* NOT Data=*_3414* 
| eval Email=upper(email) 
| append 
    [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.layers) as Data, count(Eplanner.layers) as Datacount from datamodel=Eplanner groupby _time Eplanner.email 
    | eval Email=upper(Email)] 
| append 
    [| tstats values(Eplanner.email) as Email, values(Eplanner.agency) as Agency, values(Eplanner.typename) as Data, count(Eplanner.typename) as Datacount from datamodel=Eplanner groupby _time Eplanner.email 
    | eval Email=upper(Email)] 
| lookup eplannerusers.csv "Login Name" as Email OUTPUT "Login Name" Date Group as Group Department Designation "Full Name" as Fullname 
| strcat Fullname " / " Department Name_Dept 
| search Agency="Potato Hero" Email=Potato@Hero.potato.sg Data="AreaOIC"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;The field Data comes from the values of 3 different fields from 3 different tstats statements. You can't collect all the different fields then expect to somehow filter out the unwanted ones at the end of the search,&amp;nbsp; particularly as you are combining the counts of these Data fields at each stage, so it's impossible to undo that further down your search.&lt;/P&gt;&lt;P&gt;You will need to only search for your wanted Data field in each of the tstats statements, so you need to add the&amp;nbsp;X="AreaOIC" filter criteria into each of your tstats statements, where you are collecting data, e.g.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;tstats ... values(Arcgis.mapservice) as Data .... where ... Arcgis.mapservice="AreaOIC"

tstats ... values(Eplanner.layers) as Data .... where ... Eplanner.layers="AreaOIC"

tstats ... values(Eplanner.typename) as Data .... where ... Eplanner.typename="AreaOIC"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 22:01:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-remove-event-s-from-the-values-Data-field/m-p/551505#M156505</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-05-13T22:01:18Z</dc:date>
    </item>
  </channel>
</rss>

