Splunk Search

Count of Value Pairs in URI Query String

chca
Path Finder

Assuming my URL_Query field contains the following data:


cdata=153&orgid=0012
orgid=3924&cdata=129
cdata=153&orgid=3924

How can I display a table containing a unique count of value pairs cdata?


cdata count
153 2
129 1

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee
... | extract auto=true | stats count by cdata

Actually, unless you've done something to turn it off, the fields will usually have been auto extracted by Splunk without you having to call the extract command.

0 Karma

chca
Path Finder

I also found this answer:
http://splunk-base.splunk.com/answers/8404/chart-over-query-string

However, I don't have the value pairs pre-parsed. I need to do it during the search.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...