Assuming my URL_Query field contains the following data:
cdata=153&orgid=0012
orgid=3924&cdata=129
cdata=153&orgid=3924
How can I display a table containing a unique count of value pairs cdata?
cdata count
153 2
129 1
... | extract auto=true | stats count by cdata
Actually, unless you've done something to turn it off, the fields will usually have been auto extracted by Splunk without you having to call the extract
command.
I also found this answer:
http://splunk-base.splunk.com/answers/8404/chart-over-query-string
However, I don't have the value pairs pre-parsed. I need to do it during the search.