You can use the spath command.
your_search | spath path=a{} output=name | stats count(name) as name
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Spath
You can use the spath command.
your_search | spath path=a{} output=name | stats count(name) as name
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Spath
your_search | spath path=a{} output=aName | spath path=z{} output=zName | stats count(aName) as a count(zName) as z by id
my example is too simple. for a single event
{"id": 32413
"a" : [{"b": true}, {"b": true}, {"c": true}].
"z" : [{"a": 1}, {"d":2}]}
I want this output
id a z
=============
32413 3 2