<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic multivalue fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/multivalue-fields/m-p/581238#M202497</link>
    <description>&lt;P&gt;Hi I'm trying to count the number of times of a specific values "not match" exist in a multi-value field, search for events where this value appears more then once.&lt;BR /&gt;&lt;BR /&gt;add an example&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;name&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;Check&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;ID&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="68px"&gt;&lt;P&gt;aaa-1&lt;BR /&gt;bbb-2&lt;BR /&gt;ccc-3&lt;/P&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="68px"&gt;not match&lt;BR /&gt;match&lt;BR /&gt;match&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="68px"&gt;6564&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;ddd-1&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;eee-2&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;fff-3&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;not match&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;match&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;not match&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;7875&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;because in the lower row the value "not match" exist more then 1 time (&amp;gt;1).&lt;BR /&gt;I don't found a suitable command.&lt;BR /&gt;would appreciate&amp;nbsp; help:)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 16 Jan 2022 10:37:25 GMT</pubDate>
    <dc:creator>poladbank</dc:creator>
    <dc:date>2022-01-16T10:37:25Z</dc:date>
    <item>
      <title>multivalue fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multivalue-fields/m-p/581238#M202497</link>
      <description>&lt;P&gt;Hi I'm trying to count the number of times of a specific values "not match" exist in a multi-value field, search for events where this value appears more then once.&lt;BR /&gt;&lt;BR /&gt;add an example&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;name&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;Check&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;ID&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="68px"&gt;&lt;P&gt;aaa-1&lt;BR /&gt;bbb-2&lt;BR /&gt;ccc-3&lt;/P&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="68px"&gt;not match&lt;BR /&gt;match&lt;BR /&gt;match&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="68px"&gt;6564&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;ddd-1&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;eee-2&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;fff-3&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;not match&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;match&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;not match&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;&lt;STRONG&gt;&lt;FONT&gt;7875&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;because in the lower row the value "not match" exist more then 1 time (&amp;gt;1).&lt;BR /&gt;I don't found a suitable command.&lt;BR /&gt;would appreciate&amp;nbsp; help:)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 10:37:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multivalue-fields/m-p/581238#M202497</guid>
      <dc:creator>poladbank</dc:creator>
      <dc:date>2022-01-16T10:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: multivalue fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multivalue-fields/m-p/581241#M202498</link>
      <description>&lt;LI-CODE lang="markup"&gt;| chart values(name) as name count by ID Check
| where 'count: not match' &amp;gt; 1
| rename "name: not match" as name, "count: not match" as count
| table ID name count&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 16 Jan 2022 11:15:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multivalue-fields/m-p/581241#M202498</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-01-16T11:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: multivalue fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multivalue-fields/m-p/581244#M202499</link>
      <description>&lt;P&gt;Thank you for your fast response!&lt;BR /&gt;I've tried your solution and had a problem in the where part.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jan 2022 12:10:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multivalue-fields/m-p/581244#M202499</guid>
      <dc:creator>poladbank</dc:creator>
      <dc:date>2022-01-16T12:10:56Z</dc:date>
    </item>
  </channel>
</rss>

