<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multivalue-Field Filter in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560036#M159138</link>
    <description>&lt;P&gt;Thank you for your Reply. Unfortunately that does not return any results either.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jul 2021 12:16:51 GMT</pubDate>
    <dc:creator>doki971</dc:creator>
    <dc:date>2021-07-19T12:16:51Z</dc:date>
    <item>
      <title>Multivalue-Field Filter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560011#M159132</link>
      <description>&lt;P&gt;I receive a bunch of messages that all are assigned to a group by the groupID.&lt;BR /&gt;I also have a dynamic set of a range as a Multivalue-Field, that needs to be used as a filter for these messages.&lt;BR /&gt;&lt;BR /&gt;I tried it like this so far, but couldn't get any results:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index sourcetype=my_source
| eval range=case("case1", mvrange(1,9), "case2", mvrange(10,19),...)
| where groupID in (range)
| stats count(_raw) as count by groupdID&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;So if case1 happens, i only want to see the amount of Messages in the specified groupID-range, and so on..&lt;BR /&gt;&lt;BR /&gt;Can anyone help me with that ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 09:59:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560011#M159132</guid>
      <dc:creator>doki971</dc:creator>
      <dc:date>2021-07-19T09:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: Multivalue-Field Filter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560013#M159133</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index sourcetype=my_source
| eval range=case("case1", mvrange(1,9), "case2", mvrange(10,19),...)
| mvexpand range
| where groupID=range
| stats count by groupdID&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 19 Jul 2021 10:06:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560013#M159133</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-19T10:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multivalue-Field Filter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560036#M159138</link>
      <description>&lt;P&gt;Thank you for your Reply. Unfortunately that does not return any results either.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 12:16:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560036#M159138</guid>
      <dc:creator>doki971</dc:creator>
      <dc:date>2021-07-19T12:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Multivalue-Field Filter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560037#M159139</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236559"&gt;@doki971&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your approach should work.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval groupID=8
| eval range=case(groupID&amp;lt;10,mvrange(1,9))
| where groupID in (range)
| stats count by groupID&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found typo (groupdID) in your search. Is this a reason for no results?&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index sourcetype=my_source
| eval range=case("case1", mvrange(1,9), "case2", mvrange(10,19),...)
| where groupID in (range)
| stats count(_raw) as count by groupID&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;▄︻̷̿┻̿═━一 &amp;nbsp; ?&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 12:37:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560037#M159139</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-07-19T12:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Multivalue-Field Filter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560047#M159144</link>
      <description>&lt;P&gt;Thanks for your reply. Sorry about the typo, but that is not the issue because in my actual search i am using different field names anyway -&amp;nbsp; 'groupID' is just for a better visualization.&lt;BR /&gt;&lt;BR /&gt;Hower i found out that if e.g. i add&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where groupID = 8&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;meaning i just want the messages for groupID 8, i get the following error:&lt;BR /&gt;&lt;BR /&gt;Error in 'where' command: Type checking failed. The '==' operator received different types.&lt;BR /&gt;&lt;BR /&gt;Could that be the issue ?&lt;BR /&gt;&lt;BR /&gt;I also tried:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where groupID = "8"&lt;/LI-CODE&gt;&lt;P&gt;Then the search does not return an error but again also no results.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 13:06:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560047#M159144</guid>
      <dc:creator>doki971</dc:creator>
      <dc:date>2021-07-19T13:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Multivalue-Field Filter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560048#M159145</link>
      <description>&lt;LI-CODE lang="markup"&gt;| where tonumber(groupID)=8&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 19 Jul 2021 13:08:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560048#M159145</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-19T13:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Multivalue-Field Filter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560057#M159147</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;So Here is a little follow up, as i am still not able to get any results:&lt;BR /&gt;&lt;BR /&gt;These are the results without the 'where' clause:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image001.jpg" style="width: 970px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15151i0410B20F9226E562/image-size/large?v=v2&amp;amp;px=999" role="button" title="image001.jpg" alt="image001.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index sourcetype=my_sourcetype
| stats count by groupID​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So e.g. there are 2398465 Events for the groupID 492.&lt;BR /&gt;&lt;BR /&gt;However as soon as i add the 'where' clause:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index sourcetype=my_sourcetype
| eval range=mvrange(492,545)
| where groupID in (range)
| stats count by groupID​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not getting any results anymore.&lt;BR /&gt;&lt;BR /&gt;Same goes for the above suggestions with:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| where groupID=492
  OR
| where tonumber(groupID)=492
  OR
| where groupID="492"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Any more ideas ?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 13:38:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560057#M159147</guid>
      <dc:creator>doki971</dc:creator>
      <dc:date>2021-07-19T13:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Multivalue-Field Filter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560059#M159148</link>
      <description>&lt;P&gt;Try it the other way around&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=my_index sourcetype=my_sourcetype
| stats count by groupID​
| eval range=mvrange(492,546)
| where groupID in (range)&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 19 Jul 2021 13:43:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560059#M159148</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-19T13:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Multivalue-Field Filter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560060#M159149</link>
      <description>&lt;P&gt;Sadly didn't change anything&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 13:46:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560060#M159149</guid>
      <dc:creator>doki971</dc:creator>
      <dc:date>2021-07-19T13:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Multivalue-Field Filter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560063#M159151</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236559"&gt;@doki971&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you can share about the condition in case statements then we can search for optimum solution.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval range=case("case1", mvrange(1,9), "case2", mvrange(10,19),...)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;like,&amp;nbsp;case1 &amp;amp;&amp;nbsp;case2.. &amp;nbsp;how many case are there, etc&lt;/P&gt;&lt;P&gt;/&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 13:49:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560063#M159151</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-07-19T13:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Multivalue-Field Filter</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560065#M159152</link>
      <description>&lt;P&gt;I am currently trying to get any results, hence why i left the 'case' statement out for now.&lt;BR /&gt;However here are the cases i will need for the future:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval range=case("case1", mvrange(493,511), "case2", mvrange(436,448), "case3", mvrange(470,480))&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 19 Jul 2021 13:57:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Multivalue-Field-Filter/m-p/560065#M159152</guid>
      <dc:creator>doki971</dc:creator>
      <dc:date>2021-07-19T13:57:17Z</dc:date>
    </item>
  </channel>
</rss>

