Splunk Search

how do I count values based on many values using a multiselect filter

Talking_Master
Explorer

Hi I am trying to count values based on values if they equal a range of values. Is that possible? 

| search fieldName=$Token $
| stats count(eval(fieldName)) AS Label by FieldName
| table FieldName

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Talking_Master,

one information: you used "fieldName" and "FieldName": are they two different fields or it's a mistyping?

if it's a mistyping, you can simplify your search:

| search fieldName=$Token $
| stats count AS Label by FieldName
| table FieldName

if they are two different fields, you don't need to use the eval in the stats count command.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...