Splunk Search

Hi Experts, I would like to count the multifield in the table where it has similar values

Ashwini_5
Explorer

I would like to count the multifield in the table where it has similar values. 

For Ex:  I need output like below for the COMPLETED_CERT_COUNT, It should only show the count of NOT_Expired training status. 

Ashwini_5_0-1642787628604.png

 

I have tried |eval COMPLETED_CERT_COUNT=mvcount(if(TRAINING_STATUS=="Not_Expired")) and

 

| stats mvcount(eval(TRAINING_STATUS="Not_Expired")) as certcount by name . But Nothing worked out. Kindly share your suggestion 

Labels (1)
Tags (1)
0 Karma

somesoni2
Revered Legend

Try something like this

|eval COMPLETED_CERT_COUNT=mvcount(mvfilter(match(TRAINING_STATUS,"Not_Expired"))) 
0 Karma

diogofgm
SplunkTrust
SplunkTrust

You could try to user mvexpand to expand the training_status and then do a stats count(eval(TRAINING_STATUS="Not_Expired")) as certcount by name

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...