<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to find the number of fields that consists &amp;quot;Passed&amp;quot; and also the Total number of fields available. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557388#M158301</link>
    <description>&lt;P&gt;&lt;SPAN&gt;This is the _raw data i filtered like this. i want to know the count of the total "passed"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Dns Rule=Passed, HOSTNAME=Passed, username=Passed, ssh Timeout rule=Passed snmp rule=Passed, udld Rule=Passed, Enable Password=Passed, Snmp config rule=Passed, Line Vty 0 4 Timeout &amp;amp; acl=Passed, Line Con 0 timeout=Passed, Service Policy=Passed, Https Rule=Passed, Line Con 0=Passed, Line aux 0=Passed, Don't Username=Passed, Service Password Encryption=Passed, Aaa Server-GE=Passed, Line Vty 5 15=Passed, Image Verification=Passed, Bootp Server=Passed,Line Vty 0 4=Passed,&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jun 2021 09:35:43 GMT</pubDate>
    <dc:creator>vinod743374</dc:creator>
    <dc:date>2021-06-28T09:35:43Z</dc:date>
    <item>
      <title>How to find the number of fields that consists "Passed" and also the Total number of fields available.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557384#M158298</link>
      <description>&lt;P&gt;This is my sample data. i need the total "passed"&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are the Headers, Node Name _time, Anti-Spoofing,&amp;nbsp; Rule Banner , Rule Http Rule Palo alto Username SSH Timeout Ssh Access Tacacs Telnet Rule console port config ntp server Result&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;NDL-ALM-GSD-BUS-FW-01&lt;/TD&gt;&lt;TD&gt;2021-06-24 17:27:35&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;USA-DNV-CUS-BUS-FW-02&lt;/TD&gt;&lt;TD&gt;2021-06-24 17:27:35&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;TD&gt;Passed&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 28 Jun 2021 09:21:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557384#M158298</guid>
      <dc:creator>vinod743374</dc:creator>
      <dc:date>2021-06-28T09:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the number of fields that consists "Passed" and also the Total number of fields available.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557385#M158299</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234515"&gt;@vinod743374&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please share sample _raw events and expected OP from that event?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 09:30:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557385#M158299</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-28T09:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the number of fields that consists "Passed" and also the Total number of fields available.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557388#M158301</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This is the _raw data i filtered like this. i want to know the count of the total "passed"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Dns Rule=Passed, HOSTNAME=Passed, username=Passed, ssh Timeout rule=Passed snmp rule=Passed, udld Rule=Passed, Enable Password=Passed, Snmp config rule=Passed, Line Vty 0 4 Timeout &amp;amp; acl=Passed, Line Con 0 timeout=Passed, Service Policy=Passed, Https Rule=Passed, Line Con 0=Passed, Line aux 0=Passed, Don't Username=Passed, Service Password Encryption=Passed, Aaa Server-GE=Passed, Line Vty 5 15=Passed, Image Verification=Passed, Bootp Server=Passed,Line Vty 0 4=Passed,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 09:35:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557388#M158301</guid>
      <dc:creator>vinod743374</dc:creator>
      <dc:date>2021-06-28T09:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the number of fields that consists "Passed" and also the Total number of fields available.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557389#M158302</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234515"&gt;@vinod743374&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;YOUR_SEARCH 
| rex field=_raw "=(?&amp;lt;a&amp;gt;Passed)" max_match=0 | eval count=mvcount(a) | fields - a&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Sample Search :&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval _raw="Dns Rule=Passed, HOSTNAME=Passed, username=Passed, ssh Timeout rule=Passed snmp rule=Passed, udld Rule=Passed, Enable Password=Passed, Snmp config rule=Passed, Line Vty 0 4 Timeout &amp;amp; acl=Passed, Line Con 0 timeout=Passed, Service Policy=Passed, Https Rule=Passed, Line Con 0=Passed, Line aux 0=Passed, Don't Username=Passed, Service Password Encryption=Passed, Aaa Server-GE=Passed, Line Vty 5 15=Passed, Image Verification=Passed, Bootp Server=Passed,Line Vty 0 4=Passed" 
|rename comment as "Upto Now is sample data only" 
| rex field=_raw "=(?&amp;lt;a&amp;gt;Passed)" max_match=0 | eval count=mvcount(a)  | fields - a&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 09:41:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557389#M158302</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-28T09:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the number of fields that consists "Passed" and also the Total number of fields available.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557392#M158304</link>
      <description>&lt;P&gt;Thank you so much ,&lt;BR /&gt;its is working .&lt;BR /&gt;but if in the place of Passed,&amp;nbsp; i have some Failed message like :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Critical - Pattern 'disable-http yes' was not found Pattern 'https yes' was not found&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can we count these Error Failed messages&amp;nbsp;also ???&lt;BR /&gt;kindly help me with this also.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 10:14:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557392#M158304</guid>
      <dc:creator>vinod743374</dc:creator>
      <dc:date>2021-06-28T10:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the number of fields that consists "Passed" and also the Total number of fields available.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557393#M158305</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234515"&gt;@vinod743374&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;YOUR_SEARCH
| rex field=_raw "=(?&amp;lt;a&amp;gt;Passed)" max_match=0 | eval passed_count=mvcount(a) | fields - a
| rex field=_raw "=(?&amp;lt;a&amp;gt;Failed)" max_match=0 | eval failed_count=mvcount(a) | fields - a&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Sample Search :&lt;/STRONG&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval _raw="Dns Rule=Passed, HOSTNAME=Passed, username=Passed, ssh Timeout rule=Passed snmp rule=Passed, udld Rule=Passed, Enable Password=Passed, Snmp config rule=Passed, Line Vty 0 4 Timeout &amp;amp; acl=Passed, Line Con 0 timeout=Passed, Service Policy=Passed, Https Rule=Passed, Line Con 0=Passed, Line aux 0=Passed, Don't Username=Passed, Service Password Encryption=Passed, Aaa Server-GE=Passed, Line Vty 5 15=Passed, Image Verification=Passed, Bootp Server=Passed,Line Vty 0 4=Passed, xyz=Failed" 
|rename comment as "Upto Now is sample data only" 
| rex field=_raw "=(?&amp;lt;a&amp;gt;Passed)" max_match=0 | eval passed_count=mvcount(a) | fields - a
| rex field=_raw "=(?&amp;lt;a&amp;gt;Failed)" max_match=0 | eval failed_count=mvcount(a) | fields - a&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 10:17:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557393#M158305</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-28T10:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the number of fields that consists "Passed" and also the Total number of fields available.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557396#M158307</link>
      <description>&lt;P&gt;Its not gonna workout ,&lt;BR /&gt;because there is no such "Failed" in the _raw&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;let me share you the _raw event of that .&amp;nbsp; i just bold the failed message.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class="t"&gt;Dns&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Rule=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;HOSTNAME=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;username=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;ssh&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Timeout&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rule=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Node&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Name=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;HUN-BUD-GE-COR-SW-01_stack.ROMA.AD&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;snmp&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rule=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;udld&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Rule=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Enable&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Password=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Snmp&lt;/SPAN&gt; &lt;SPAN class="t"&gt;config&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rule=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Vty&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;4&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Timeout&lt;/SPAN&gt;&lt;SPAN&gt; &amp;amp; &lt;/SPAN&gt;&lt;SPAN class="t"&gt;acl=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Con&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;timeout=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Service&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Policy=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Https&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Rule=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Con&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;aux&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Node&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Ip&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Address=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;10.198.4.1&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Don&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;t&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Username=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Service&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Password&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Encryption=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Aaa&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Server-GE=&lt;/SPAN&gt;&lt;STRONG&gt;"&lt;SPAN class="t"&gt;Critical&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Pattern&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;aaa&lt;/SPAN&gt; &lt;SPAN class="t"&gt;new-model&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;was&lt;/SPAN&gt; &lt;SPAN class="t"&gt;found&lt;/SPAN&gt; &lt;SPAN class="t"&gt;On&lt;/SPAN&gt; &lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;28&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;aaa&lt;/SPAN&gt; &lt;SPAN class="t"&gt;new-model&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;Pattern&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;aaa&lt;/SPAN&gt; &lt;SPAN class="t"&gt;authentication&lt;/SPAN&gt; &lt;SPAN class="t"&gt;login&lt;/SPAN&gt; &lt;SPAN class="t"&gt;default&lt;/SPAN&gt; &lt;SPAN class="t"&gt;group&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tacacs&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;was&lt;/SPAN&gt; &lt;SPAN class="t"&gt;not&lt;/SPAN&gt; &lt;SPAN class="t"&gt;found&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Pattern&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;aaa&lt;/SPAN&gt; &lt;SPAN class="t"&gt;authorization&lt;/SPAN&gt; &lt;SPAN class="t"&gt;exec&lt;/SPAN&gt; &lt;SPAN class="t"&gt;default&lt;/SPAN&gt; &lt;SPAN class="t"&gt;group&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tacacs&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;was&lt;/SPAN&gt; &lt;SPAN class="t"&gt;not&lt;/SPAN&gt; &lt;SPAN class="t"&gt;found&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Pattern&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;aaa&lt;/SPAN&gt; &lt;SPAN class="t"&gt;accounting&lt;/SPAN&gt; &lt;SPAN class="t"&gt;exec&lt;/SPAN&gt; &lt;SPAN class="t"&gt;default&lt;/SPAN&gt; &lt;SPAN class="t"&gt;start-stop&lt;/SPAN&gt; &lt;SPAN class="t"&gt;group&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tacacs&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;was&lt;/SPAN&gt; &lt;SPAN class="t"&gt;not&lt;/SPAN&gt; &lt;SPAN class="t"&gt;found&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Pattern&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;tacacs-server&lt;/SPAN&gt; &lt;SPAN class="t"&gt;host&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10.198.60.40&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;was&lt;/SPAN&gt; &lt;SPAN class="t"&gt;not&lt;/SPAN&gt; &lt;SPAN class="t"&gt;found&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Pattern&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;tacacs-server&lt;/SPAN&gt; &lt;SPAN class="t"&gt;host&lt;/SPAN&gt; &lt;SPAN class="t"&gt;10.198.40.40&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;was&lt;/SPAN&gt; &lt;SPAN class="t"&gt;not&lt;/SPAN&gt; &lt;SPAN class="t"&gt;found&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Pattern&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;tacacs-server&lt;/SPAN&gt; &lt;SPAN class="t"&gt;directed-request&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;was&lt;/SPAN&gt; &lt;SPAN class="t"&gt;not&lt;/SPAN&gt; &lt;SPAN class="t"&gt;found&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Pattern&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;aaa&lt;/SPAN&gt; &lt;SPAN class="t"&gt;authentication&lt;/SPAN&gt; &lt;SPAN class="t"&gt;enable&lt;/SPAN&gt; &lt;SPAN class="t"&gt;default&lt;/SPAN&gt; &lt;SPAN class="t"&gt;group&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tacacs&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;was&lt;/SPAN&gt; &lt;SPAN class="t"&gt;not&lt;/SPAN&gt; &lt;SPAN class="t"&gt;found&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Pattern&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;aaa&lt;/SPAN&gt; &lt;SPAN class="t"&gt;accounting&lt;/SPAN&gt; &lt;SPAN class="t"&gt;commands&lt;/SPAN&gt; &lt;SPAN class="t"&gt;15&lt;/SPAN&gt; &lt;SPAN class="t"&gt;default&lt;/SPAN&gt; &lt;SPAN class="t"&gt;start-stop&lt;/SPAN&gt; &lt;SPAN class="t"&gt;group&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tacacs&lt;/SPAN&gt;' &lt;SPAN class="t"&gt;was&lt;/SPAN&gt; &lt;SPAN class="t"&gt;not&lt;/SPAN&gt; &lt;SPAN class="t"&gt;found&lt;/SPAN&gt;", &lt;/STRONG&gt;&lt;SPAN class="t"&gt;Line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Vty&lt;/SPAN&gt; &lt;SPAN class="t"&gt;5&lt;/SPAN&gt; &lt;SPAN class="t"&gt;15=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Image&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Verification=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Bootp&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Server=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Config&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Title=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;4/26/2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;01:03&lt;/SPAN&gt; &lt;SPAN class="t"&gt;PM&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Running&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Vty&lt;/SPAN&gt; &lt;SPAN class="t"&gt;0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;4=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Logging&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Rule=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Banner&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Rule=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Config&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Type=Running&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Finger&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Rule=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Http&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Server=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Name&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Server=Passed&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;Pad&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Service=Passed&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 10:27:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557396#M158307</guid>
      <dc:creator>vinod743374</dc:creator>
      <dc:date>2021-06-28T10:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the number of fields that consists "Passed" and also the Total number of fields available.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557401#M158310</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234515"&gt;@vinod743374&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that specific pattern that we can say Failed for this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;AaaServer-GE="Critical - Pattern 'aaa new-model' was found On line 28 'aaa new-model' Pattern 'aaa authentication login default group tacacs' was not found Pattern 'aaa authorization exec default group tacacs' was not found Pattern 'aaa accounting exec default start-stop group tacacs' was not found Pattern 'tacacs-server host 10.198.60.40' was not found Pattern 'tacacs-server host 10.198.40.40' was not found Pattern 'tacacs-server directed-request' was not found Pattern 'aaa authentication enable default group tacacs' was not found Pattern 'aaa accounting commands 15 default start-stop group tacacs' was not found"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 10:50:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557401#M158310</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-28T10:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the number of fields that consists "Passed" and also the Total number of fields available.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557402#M158311</link>
      <description>&lt;P&gt;Yes,&lt;BR /&gt;the Content may changes for different Events.&lt;BR /&gt;&lt;BR /&gt;"Critical - "&amp;nbsp; is common in all the things the remaining&amp;nbsp; gets changed.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 10:55:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557402#M158311</guid>
      <dc:creator>vinod743374</dc:creator>
      <dc:date>2021-06-28T10:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the number of fields that consists "Passed" and also the Total number of fields available.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557403#M158312</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234515"&gt;@vinod743374&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;YOUR_SEARCH
| rex field=_raw "=(?&amp;lt;a&amp;gt;Passed)" max_match=0 
| rex field=_raw "=\"(?&amp;lt;b&amp;gt;Critical\s-) " max_match=0 
| eval passed_count=mvcount(a), failed_count=mvcount(b) | fields - a,b&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 10:59:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557403#M158312</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-28T10:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the number of fields that consists "Passed" and also the Total number of fields available.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557405#M158313</link>
      <description>&lt;P&gt;Thank you so much it is working.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 11:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557405#M158313</guid>
      <dc:creator>vinod743374</dc:creator>
      <dc:date>2021-06-28T11:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the number of fields that consists "Passed" and also the Total number of fields available.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557407#M158314</link>
      <description>&lt;P&gt;Glad to help you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234515"&gt;@vinod743374&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But you supposed to accept my last answer &amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 11:10:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-number-of-fields-that-consists-quot-Passed-quot/m-p/557407#M158314</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-06-28T11:10:21Z</dc:date>
    </item>
  </channel>
</rss>

