Splunk Search

how do I count values based on many values using a multiselect filter

Talking_Master
Explorer

Hi I am trying to count values based on values if they equal a range of values. Is that possible? 

| search fieldName=$Token $
| stats count(eval(fieldName)) AS Label by FieldName
| table FieldName

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Talking_Master,

one information: you used "fieldName" and "FieldName": are they two different fields or it's a mistyping?

if it's a mistyping, you can simplify your search:

| search fieldName=$Token $
| stats count AS Label by FieldName
| table FieldName

if they are two different fields, you don't need to use the eval in the stats count command.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...