Splunk Search

Is it possible to exclude any events with multi value fields and only table ones with single value?

FGAnders
Explorer


Hi,

Is there any way to exclude any events that has more than one value of a field  from end result. 

 

index=X status=1
| rex field=_raw Product\W.(?P<Product>\w*)  
| rex field=_raw englishName\W.\W(?P<englishName>\w*.*\w)\W
| rex field=_raw name\W.\W(?P<name>\w*.*\w)
| eval indexTime=_indextime | sort + indexTime | stats list(name) as Customer, list(transaction) as amount, list(Product) as Products, list(currency) as currency, list(englishName) as Item | fieldformat Time = strftime(Time, "%Y-%m-%d %H:%M:%S") | 

 

 

Data from Event

 

name: "JohnA",selection=2,Product: "ABC",description=<null>,country='MT',selection=1,Product: "??",description=<null>,country='MT',selection=2,Product: "GOLD",description=<null>,country='MT',

 

 

While Having other results where there is only one Product in the events. I would like to exclude any events where there is more than 1 Product. I do not want them in the result. I have tried to find out if there is an option to have rex max_match to only show the ones with max 1 result. Without any luck.

Thank you in advanced,

Labels (4)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| rex field=_raw max_match=2 Product\W.(?P<Product>\w*)
| where mvcount(Product) = 1

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| rex field=_raw max_match=2 Product\W.(?P<Product>\w*)
| where mvcount(Product) = 1

FGAnders
Explorer

Thank you very much

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...