<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Show all possible values in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696610#M236745</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ive entered&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;INTERNAL_VALIDATION_FAILED| spath
| rex field=statusMessage "\[(?&amp;lt;ds_message&amp;gt;[^\]]+)"
| spath input=ds_message
| stats count by errorDetail&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And there is only&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;"errorDetail\":&amp;nbsp; + count of events&lt;/STRONG&gt; without values.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="weird_guy_0-1723960844448.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32279i06329DB4108F0223/image-size/medium?v=v2&amp;amp;px=400" role="button" title="weird_guy_0-1723960844448.png" alt="weird_guy_0-1723960844448.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="weird_guy_1-1723960860658.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32280i7E47211A058D7A30/image-size/medium?v=v2&amp;amp;px=400" role="button" title="weird_guy_1-1723960860658.png" alt="weird_guy_1-1723960860658.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 18 Aug 2024 09:12:50 GMT</pubDate>
    <dc:creator>weird_guy</dc:creator>
    <dc:date>2024-08-18T09:12:50Z</dc:date>
    <item>
      <title>Show all possible values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696587#M236739</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;I have a lot of events. Each event contains similar string&amp;nbsp;&lt;STRONG&gt;\"errorDetail\":\"possible_value\"&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Please specify how to create new field &lt;STRONG&gt;\"errorDetail\"&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp; &lt;STRONG&gt;stats&lt;/STRONG&gt; all possible values? (There are more than 50 kinds of&amp;nbsp;&lt;STRONG&gt;errorDetail&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;\"errorDetail\":\"acctNumber\"&amp;nbsp;&lt;BR /&gt;\"errorDetail\":\"Message Version higher"\&lt;BR /&gt;\"errorDetail\":\"email\"&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 16:18:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696587#M236739</guid>
      <dc:creator>weird_guy</dc:creator>
      <dc:date>2024-08-17T16:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Show all possible values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696588#M236740</link>
      <description>&lt;P&gt;This looks like JSON format data - if so, you should be extracting as JSON and using the JSON functions to manipulate the data. Please share your full event in raw format in a code block, anonymise your data as appropriate. This will enable volunteers to better guide you on a way forward.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 16:25:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696588#M236740</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-17T16:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: Show all possible values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696590#M236741</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the raw data:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{

"messageType": "Data",
"status": "Error",
"statusMessage": "invalid message fields, wrong message from ds:[{\"threeDSServerTransID\":\"123\",\"messageType\":\"Erro\",\"messageVersion\":\"2.2.0\",\"acsTransID\":\"123\",\"dsTransID\":\"123\",\"errorCode\":\"305\",\"errorComponent\":\"A\",\"errorDescription\":\"Transaction data not valid\",\"errorDetail\":\"No issuer found\",\"errorMessageType\":\"AReq\"}]; type[Erro] code[101] component[SERVER]"

}&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 17 Aug 2024 22:33:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696590#M236741</guid>
      <dc:creator>weird_guy</dc:creator>
      <dc:date>2024-08-17T22:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Show all possible values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696591#M236742</link>
      <description>&lt;P&gt;From your raw event you could do this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| spath
| rex field=statusMessage "\[(?&amp;lt;ds_message&amp;gt;[^\]]+)"
| spath input=ds_message
| stats count by errorDetail&lt;/LI-CODE&gt;&lt;P&gt;if you have already extracted statusMessage when the event was ingested, you can skip the first spath command&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 17:16:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696591#M236742</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-17T17:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Show all possible values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696597#M236743</link>
      <description>&lt;P&gt;Ugh. That's a pretty example of ugly data. Technically your data is a json structure with a field containing a string. That string describes another json structure but from splunk's point of view it's just a string. That makes it very inconvenient and possibly inefficient to manipulate. It would be much better if you got this from your source as some more sane format.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 20:44:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696597#M236743</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-17T20:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Show all possible values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696610#M236745</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ive entered&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;INTERNAL_VALIDATION_FAILED| spath
| rex field=statusMessage "\[(?&amp;lt;ds_message&amp;gt;[^\]]+)"
| spath input=ds_message
| stats count by errorDetail&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And there is only&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;"errorDetail\":&amp;nbsp; + count of events&lt;/STRONG&gt; without values.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="weird_guy_0-1723960844448.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32279i06329DB4108F0223/image-size/medium?v=v2&amp;amp;px=400" role="button" title="weird_guy_0-1723960844448.png" alt="weird_guy_0-1723960844448.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="weird_guy_1-1723960860658.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32280i7E47211A058D7A30/image-size/medium?v=v2&amp;amp;px=400" role="button" title="weird_guy_1-1723960860658.png" alt="weird_guy_1-1723960860658.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 09:12:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696610#M236745</guid>
      <dc:creator>weird_guy</dc:creator>
      <dc:date>2024-08-18T09:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Show all possible values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696620#M236746</link>
      <description>&lt;P&gt;Here is a runanywhere example using your original event data showing the solution working. If it is not working with your real data, this means that the sample you shared is not an accurate representation of your real data. Please share an updated &lt;U&gt;accurate&lt;/U&gt; representation of your data.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 09:06:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696620#M236746</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-18T09:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: Show all possible values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696622#M236747</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Here is an updated accurate data.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;LI-CODE lang="java"&gt;3DS2 Server ARes Response: {"messageType":"ARes","status":"INTERNAL_VALIDATION_FAILED","statusMessage":"invalid message fields, wrong message from ds:[{\"threeDSServerTransID\":\"123\",\"messageType\":\"Erro\",\"messageVersion\":\"2.2.0\",\"acsTransID\":\"345\",\"dsTransID\":\"567\",\"errorCode\":\"305\",\"errorComponent\":\"A\",\"errorDescription\":\"Cardholder Account Number is not in a range belonging to Issuer\",\"errorDetail\":\"acctNumber\",\"errorMessageType\":\"AReq\"}]; type[Erro] code[101] component[SERVER]"}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 09:15:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696622#M236747</guid>
      <dc:creator>weird_guy</dc:creator>
      <dc:date>2024-08-18T09:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Show all possible values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696627#M236750</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "Response: (?&amp;lt;response&amp;gt;\{.+\})"
| spath input=response
| rex field=statusMessage "ds:\[(?&amp;lt;ds_message&amp;gt;[^\]]+)"
| spath input=ds_message
| stats count by errorDetail&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 18 Aug 2024 10:02:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696627#M236750</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-18T10:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: Show all possible values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696629#M236751</link>
      <description>&lt;P&gt;Magic. It works.&lt;/P&gt;&lt;P&gt;But small issue here. It shows&amp;nbsp;&lt;SPAN class=""&gt;\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;errorDetail\&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Hmmm&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="weird_guy_0-1723975524936.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32282i4A9815B6555BEA03/image-size/medium?v=v2&amp;amp;px=400" role="button" title="weird_guy_0-1723975524936.png" alt="weird_guy_0-1723975524936.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 10:06:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696629#M236751</guid>
      <dc:creator>weird_guy</dc:creator>
      <dc:date>2024-08-18T10:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Show all possible values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696631#M236753</link>
      <description>&lt;P&gt;Again, here is a runanywhere example with your sample data&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="3DS2 Server ARes Response: {\"messageType\":\"ARes\",\"status\":\"INTERNAL_VALIDATION_FAILED\",\"statusMessage\":\"invalid message fields, wrong message from ds:[{\\\"threeDSServerTransID\\\":\\\"123\\\",\\\"messageType\\\":\\\"Erro\\\",\\\"messageVersion\\\":\\\"2.2.0\\\",\\\"acsTransID\\\":\\\"345\\\",\\\"dsTransID\\\":\\\"567\\\",\\\"errorCode\\\":\\\"305\\\",\\\"errorComponent\\\":\\\"A\\\",\\\"errorDescription\\\":\\\"Cardholder Account Number is not in a range belonging to Issuer\\\",\\\"errorDetail\\\":\\\"acctNumber\\\",\\\"errorMessageType\\\":\\\"AReq\\\"}]; type[Erro] code[101] component[SERVER]\"}"
| rex "Response: (?&amp;lt;response&amp;gt;\{.+\})"
| spath input=response
| rex field=statusMessage "ds:\[(?&amp;lt;ds_message&amp;gt;[^\]]+)"
| spath input=ds_message
| stats count by errorDetail&lt;/LI-CODE&gt;&lt;P&gt;If it is not working for some of your real data, then your sample is not an accurate representation of said (failing) data.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 10:09:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696631#M236753</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-18T10:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: Show all possible values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696645#M236756</link>
      <description>&lt;P&gt;There can be a small problem: the error message, or "invalid message fields, wrong message from ds" as prefaced in the raw message, is a JSON array. &amp;nbsp;You want to handle that as an entity.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "^[^{]+(?&amp;lt;response&amp;gt;.+)"
| spath input=response
| rename messageType as topMessageType ``` handle namespace conflict ```
| rex field=statusMessage "^[^\[]+(?&amp;lt;message_from_ds&amp;gt;[^\]]+\])"
| spath input=message_from_ds path={}
| mvexpand {}
| spath input={}
| dedup errorDetail
| table errorDetail&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 18 Aug 2024 20:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Show-all-possible-values/m-p/696645#M236756</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-08-18T20:06:52Z</dc:date>
    </item>
  </channel>
</rss>

