Splunk Search

How to count the distinct list values

reverse
Contributor

My results look like these:

V1    V2 
A    X Y Z Z X Y Y 
B   X X X Y Z Z X Y Y 

V2 IS A LIST.

I want to add V3 column along where V3 will show THE count OF DISTINCT VALUES OF V2.
Is this feasible?

V2 too could have distinct x y zs.

0 Karma
1 Solution

jnudell_2
Builder

Hi @reverse ,

You could try the following search:

... [ your search stuff here ] ...
| eval V3 = mvcount(mvdedup(split(V2, " ")))

To address the individual counts by each value of V2:

... [ your search stuff here ] ...
| eval key = V1 . "|" . mvjoin(V2, "|")
| mvexpand V2
| eventstats count as V2_Count by V2 key
| eval V2P = V2 . " Count = " . V2_Count
| stats values(V2P) as V3 list(V2) as V2 by key
| eval V1 = mvindex(split(key, "|"), 0)
| table V1 V2 V3

View solution in original post

0 Karma

jnudell_2
Builder

Hi @reverse ,

You could try the following search:

... [ your search stuff here ] ...
| eval V3 = mvcount(mvdedup(split(V2, " ")))

To address the individual counts by each value of V2:

... [ your search stuff here ] ...
| eval key = V1 . "|" . mvjoin(V2, "|")
| mvexpand V2
| eventstats count as V2_Count by V2 key
| eval V2P = V2 . " Count = " . V2_Count
| stats values(V2P) as V3 list(V2) as V2 by key
| eval V1 = mvindex(split(key, "|"), 0)
| table V1 V2 V3

0 Karma

reverse
Contributor

@jnudell_2- you rock!! amazing!

0 Karma

reverse
Contributor

thanks .. but didn't work ... v2 is a list .. each item in a separate line.. so there was no need for split .. i removed it .. still didn't work ..

0 Karma

reverse
Contributor

V3 gave me count of total distinct values .. i wanted count of each Xs.. Ys ans Zs... hope i am able to remove the confusion now..

0 Karma

jnudell_2
Builder

I have updated the answer, given your clarification.

0 Karma

reverse
Contributor

@Vijeta please guide.

0 Karma

reverse
Contributor

| stats count(action) as V1, list(NAMES) as V2 by SOMETHING

ABOVE IS RESULT OF THIS

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...