Splunk Search

multivalue fields

poladbank
New Member

Hi I'm trying to count the number of times of a specific values "not match" exist in a multi-value field, search for events where this value appears more then once.

add an example

nameCheckID

aaa-1
bbb-2
ccc-3

not match
match
match
6564
ddd-1
eee-2
fff-3
not match
match
not match
7875

 

because in the lower row the value "not match" exist more then 1 time (>1).
I don't found a suitable command.
would appreciate  help:)

Labels (2)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| chart values(name) as name count by ID Check
| where 'count: not match' > 1
| rename "name: not match" as name, "count: not match" as count
| table ID name count
0 Karma

poladbank
New Member

Thank you for your fast response!
I've tried your solution and had a problem in the where part.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...