Splunk Search

Splunk HELP - How to stats based on each value in array field

cheriemilk
Path Finder

Hi Team,

I have several fields which values are array. For example,

event1: ktf2="[Background_Criteria,Profile_Criteria]"
event2: ktf2="[Background_Criteria,Profile_Criteria, keyword]"
event3: ktf2="[Rating_Criteria]"

Question: How to stats based on the each element of ktf2 value??

My Expected Stats Result is:

Criteria, Count
Background_Criteria, 2
Profile_Criteria, 2
keyword, 1
Rating_Criteria, 1

1 Solution

woodcock
Esteemed Legend

The stats command is multi-value friendly as-is so just do this:

... | stats count BY ktf2

Now, assuming that the arrays are exactly as you posted and not already multi-valued fields, you can do this:

| makeresults 
| eval ktf2="[Background_Criteria,Profile_Criteria] [Background_Criteria,Profile_Criteria,keyword] [Rating_Criteria]"
| makemv ktf2
| mvexpand ktf2

| rename COMMENT AS "Everything above generates sample event data; everything below is your solution"

| rex field=ktf2 mode=sed "s/[\[\]]//g"
| eval ktf2=split(ktf2, ",")
| stats count BY ktf2

View solution in original post

0 Karma

woodcock
Esteemed Legend

The stats command is multi-value friendly as-is so just do this:

... | stats count BY ktf2

Now, assuming that the arrays are exactly as you posted and not already multi-valued fields, you can do this:

| makeresults 
| eval ktf2="[Background_Criteria,Profile_Criteria] [Background_Criteria,Profile_Criteria,keyword] [Rating_Criteria]"
| makemv ktf2
| mvexpand ktf2

| rename COMMENT AS "Everything above generates sample event data; everything below is your solution"

| rex field=ktf2 mode=sed "s/[\[\]]//g"
| eval ktf2=split(ktf2, ",")
| stats count BY ktf2
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Recap | Agentic Operations Start with Context: Build the Right Data Foundation

Agentic Operations Start with Context: Build the Right Data Foundation   By Courtney Wright, Product Marketing ...

Recap | Assisted, Augmented or Agentic? Choose Your Splunk Starting Point

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point   By Courtney Wright, Product Marketing ...

Session 2 | Beyond the Thread: Operationalizing AI with Confidence

Session 2   Beyond the Thread: Operationalizing AI with Confidence    The true power of the Cisco Data Fabric ...