Splunk Search

How to list all values of an Extracted Field?

asarran
Path Finder

Good Morning, Fellow Splunkers

I'm looking to list all events of an extracted field one time.

Example:

Extracted Field= [Direction]

However, I don't know all the possible outcomes, so I would like to list out all the values

North
West
South East
North East
East

Does anyone have an idea how I can generate this list for further reports?

Thank You,

1 Solution

masonmorales
Influencer
 base search | stats values(yourfield)

 base search | stats count by yourfield | table yourfield 

View solution in original post

masonmorales
Influencer
 base search | stats values(yourfield)

 base search | stats count by yourfield | table yourfield 

sundareshr
Legend

Couple of options

 base search | table fieldName | dedup fieldName

*OR*

base search | stats count by fieldName
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...