- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is it possible to count the number of values in a field by another field without stats?
I have a search where I am trying to determine if a sender is a threat based on several different events that are added up at the end of my search. Before that though im trying to determine how many people that a sender has sent a message too. So far ive tried mvcount but it looks like mvcount doesnt allow a count by another value. Thanks in advance.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

It appears that you posted this same question twice, is this one a duplicate of this one:
https://answers.splunk.com/answers/740480/how-to-compare-characters-in-two-fields-and-return.html#an...
If so, you should delete this one, because the other answer is more specific and has an accepted answer.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Please respond @brienhawker.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

you can use the eventstats
command, read here:
https://docs.splunk.com/Documentation/Splunk/7.2.5/SearchReference/Eventstats
try this search anywhere, i hope it explains it well:
| makeresults count=5
| eval sender = "badguy,goodguy,neutralguy"
| makemv delim="," sender
| mvexpand sender
| eval recipients = case(sender=="badguy","1;;;2;;;3;;;4;;;5",sender=="neutralguy","1;;;2;;;3",sender=="goodguy","1")
| makemv delim=";;;" recipients
| mvexpand recipients
| eval message = "random message"
| eventstats dc(recipients) as unique_recipients by sender
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Can you say more about why you don't want to use stats? Can you share an example search? Have you looked at other commands like chart or eventstats?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Your eventstats recommendation worked. Thank you.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Im not wanting to use stats because im needing to just count the number of recipients by sender mid search and from what ive tried I havent had much success from it. Im completly open if there is a way to do it.
