Splunk Search
Highlighted

How to get all field values from large "| stats values(field)" command?

Esteemed Legend

Any search that has many field values and ends in "| stats values(field)" will show a short list of field values followed by "[and xxx more values]". How can I get all of the values?

Tags (2)
Highlighted

Re: How to get all field values from large "| stats values(field)" command?

Splunk Employee
Splunk Employee

There are varying ways, depending on the end goal:

You can list them all horizontally in a separated list

... | stats values(said_field) as said_field | mvcombine delim=" " said_field

You can list them in separate results

... | stats values(said_field) as said_field | mvexpand said_field

...and others.

View solution in original post

Highlighted

Re: How to get all field values from large "| stats values(field)" command?

Path Finder

Thank you.

0 Karma