Splunk Search

count events in multivalue field

perlish
Communicator

Hi,
I want to deal the multivalue field to get the counts whch is satisfied the conditions I set. For example, in the following picture, I want to get search result of (myfield>44) in one event.
alt text

0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

HI

Can you please try this?

YOUR_SEARCH
| eval myfield=mvfilter(myfield>44) 
| eval n=mvcount(myfield)

My Sample search:

| makeresults 
| eval myfield="10,20,30,40" 
| makemv delim="," myfield 
| eval myfield=mvfilter(myfield>20) 
| eval n=mvcount(myfield)

Thanks

View solution in original post

cmerriman
Super Champion

try this:

|eval myfield_count=mvcount(mvfilter(myfield>44))

perlish
Communicator

Thanks! It works!

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

HI

Can you please try this?

YOUR_SEARCH
| eval myfield=mvfilter(myfield>44) 
| eval n=mvcount(myfield)

My Sample search:

| makeresults 
| eval myfield="10,20,30,40" 
| makemv delim="," myfield 
| eval myfield=mvfilter(myfield>20) 
| eval n=mvcount(myfield)

Thanks

perlish
Communicator

It works,thank you!
While I have another question, it seems that splunk parse the float to string sometimes, and because of this problem, the mvfilter function may become invalid. How can I solve it in this situation?

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

Hih @perlish

Can you please share events or sample data which causes an error?

0 Karma

perlish
Communicator

I'm sorry that I don't have the sample data. When I tried to solve the question I asked ,I used nomv() method and found that the single value's type is string. Therefore, I asked the following question.

0 Karma

andrey2007
Contributor

try this command
| eval n=mvcount(myfield)

0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...