Count number of events by item in a JSON Array

New Member

Use case, I have JSON events that contain an array of US states. I want to count the number of events by state.

For instance
Event 1:

Event 2:

the query would produce results of:
NY 2
MA 1
ME 1
FL 1
NM 1


Tags (1)
0 Karma


Assuming you properly ingested the data using a _json sourcetype, it would be done like as below. The "state" field name should be automatically extracted, but you did not say what it was in your question. The assumption is that Splunk is properly parsing the json which will give you a [State] field in a multi-valued field. You can then just expand the field and get a count of each.

| mvexpand [State]
| stats count by [State]
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!