Splunk Search

count rex output within one line?

mmattek
Path Finder

if I'm want to use a rex to pull out values at want to use the ?<xcount> psuedo-field to use in a chart, is this possible:

so Select * from xxx where id in (1,3,4,xxx,54..).. i want a field that gets me a count of the values in the IN clause there.

Is this even possible?

Tags (2)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

It is, but it's not really a very good way of using Splunk if that's your main purpose:

... | rex "\((?<id>[^\(\)]*)\)" | rex max_match=99999 field=id ",?(<v>[^,]*),?" | eval c=mvcount(v)

Another way of doing this is:

... | eval c = len(replace(_raw,"[^,]","")) + 1

(or rex out the list first if there might be other commas in the _raw field, and I'm assuming the list can't be empty.)

It would be a lot better if you perhaps described to us where the source data originally comes from and whether there's a better way to get your result. It is also sometimes useful if you let us know what you are going to do with this count, in case the ultimate result is easier or better than simply counting

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

It is, but it's not really a very good way of using Splunk if that's your main purpose:

... | rex "\((?<id>[^\(\)]*)\)" | rex max_match=99999 field=id ",?(<v>[^,]*),?" | eval c=mvcount(v)

Another way of doing this is:

... | eval c = len(replace(_raw,"[^,]","")) + 1

(or rex out the list first if there might be other commas in the _raw field, and I'm assuming the list can't be empty.)

It would be a lot better if you perhaps described to us where the source data originally comes from and whether there's a better way to get your result. It is also sometimes useful if you let us know what you are going to do with this count, in case the ultimate result is easier or better than simply counting

gkanapathy
Splunk Employee
Splunk Employee

The two examples I gave are intended to do that.

0 Karma

mmattek
Path Finder

Sorry, we actually fixed this problem by having them add logging.. but here was the problem.. there is a SQL statement in the log with a Select blah in (x, y, z)... I needed the COUNT of items in the IN clause (in the parens).

0 Karma

Stephen_Sorkin
Splunk Employee
Splunk Employee

I don't quite understand the question. Could you give a line or two of data (either raw or in tabular form) as well as the answer you want to get?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...