Splunk Search

how do I count values based on many values using a multiselect filter

Talking_Master
Explorer

Hi I am trying to count values based on values if they equal a range of values. Is that possible? 

| search fieldName=$Token $
| stats count(eval(fieldName)) AS Label by FieldName
| table FieldName

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Talking_Master,

one information: you used "fieldName" and "FieldName": are they two different fields or it's a mistyping?

if it's a mistyping, you can simplify your search:

| search fieldName=$Token $
| stats count AS Label by FieldName
| table FieldName

if they are two different fields, you don't need to use the eval in the stats count command.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...