Splunk Search

How to list all values of an Extracted Field?

asarran
Path Finder

Good Morning, Fellow Splunkers

I'm looking to list all events of an extracted field one time.

Example:

Extracted Field= [Direction]

However, I don't know all the possible outcomes, so I would like to list out all the values

North
West
South East
North East
East

Does anyone have an idea how I can generate this list for further reports?

Thank You,

1 Solution

masonmorales
Influencer
 base search | stats values(yourfield)

 base search | stats count by yourfield | table yourfield 

View solution in original post

masonmorales
Influencer
 base search | stats values(yourfield)

 base search | stats count by yourfield | table yourfield 

sundareshr
Legend

Couple of options

 base search | table fieldName | dedup fieldName

*OR*

base search | stats count by fieldName
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...