Splunk Search

Count number of values in multi-valued field

LAcioffi
Explorer

Hello!

In any event i have two fields, something like:

User - Bob
Hobbies - Singing, Dancing, Eating

The "Hobbies" field is a multivalued field, and i want the output to be something like this:

User - Bob
Hobbies_Number - 3
Hobbies - Singing, Dancing, Eating

TL;DR - Is there an easy way to count how many values are in a multivalued field and show it?

Thanks in advance!

0 Karma
1 Solution

rjthibod
Champion

use the mvcount eval function

... | eval Hobbies_Number = mvcount(Hobbies)

View solution in original post

rjthibod
Champion

use the mvcount eval function

... | eval Hobbies_Number = mvcount(Hobbies)

Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...