Splunk Search

How to find Fieldnames which have some strings

zegg
Engager

If there are events like these.
And I want  to find Fieldnames which have "abc"

Event 1 

File : abcdefg

URL : 1232323232.com

NUM : 1234567899

Name : James

Event 2

File : abcdefg

URL : 1232323232.abc

NUM : 1234567899

Name : James

 

File has "abc" 2 times and URL has "abc" 1 time.
I want result like this

FieldNameCount
File2
URL1



How can I make this result by SPL?

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| foreach *
    [| eval <<FIELD>>=if(like(<<FIELD>>,"%abc%"),1,null())]
| stats sum(*) as *
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...