Splunk Search

How to list all values of an Extracted Field?

Path Finder

Good Morning, Fellow Splunkers

I'm looking to list all events of an extracted field one time.

Example:

Extracted Field= [Direction]

However, I don't know all the possible outcomes, so I would like to list out all the values

North
West
South East
North East
East

Does anyone have an idea how I can generate this list for further reports?

Thank You,

1 Solution

Influencer
 base search | stats values(yourfield)

 base search | stats count by yourfield | table yourfield 

View solution in original post

Influencer
 base search | stats values(yourfield)

 base search | stats count by yourfield | table yourfield 

View solution in original post

Legend

Couple of options

 base search | table fieldName | dedup fieldName

*OR*

base search | stats count by fieldName
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!