Splunk Search

Count number of values in multi-valued field

Explorer

Hello!

In any event i have two fields, something like:

User - Bob
Hobbies - Singing, Dancing, Eating

The "Hobbies" field is a multivalued field, and i want the output to be something like this:

User - Bob
Hobbies_Number - 3
Hobbies - Singing, Dancing, Eating

TL;DR - Is there an easy way to count how many values are in a multivalued field and show it?

Thanks in advance!

0 Karma
1 Solution

Champion

use the mvcount eval function

... | eval Hobbies_Number = mvcount(Hobbies)

View solution in original post

Champion

use the mvcount eval function

... | eval Hobbies_Number = mvcount(Hobbies)

View solution in original post

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!