Splunk Search

Is it possible to exclude any events with multi value fields and only table ones with single value?

FGAnders
Explorer


Hi,

Is there any way to exclude any events that has more than one value of a field  from end result. 

 

index=X status=1
| rex field=_raw Product\W.(?P<Product>\w*)  
| rex field=_raw englishName\W.\W(?P<englishName>\w*.*\w)\W
| rex field=_raw name\W.\W(?P<name>\w*.*\w)
| eval indexTime=_indextime | sort + indexTime | stats list(name) as Customer, list(transaction) as amount, list(Product) as Products, list(currency) as currency, list(englishName) as Item | fieldformat Time = strftime(Time, "%Y-%m-%d %H:%M:%S") | 

 

 

Data from Event

 

name: "JohnA",selection=2,Product: "ABC",description=<null>,country='MT',selection=1,Product: "??",description=<null>,country='MT',selection=2,Product: "GOLD",description=<null>,country='MT',

 

 

While Having other results where there is only one Product in the events. I would like to exclude any events where there is more than 1 Product. I do not want them in the result. I have tried to find out if there is an option to have rex max_match to only show the ones with max 1 result. Without any luck.

Thank you in advanced,

Labels (4)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| rex field=_raw max_match=2 Product\W.(?P<Product>\w*)
| where mvcount(Product) = 1

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| rex field=_raw max_match=2 Product\W.(?P<Product>\w*)
| where mvcount(Product) = 1

FGAnders
Explorer

Thank you very much

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...