Splunk Search

using spl to pick random names from list

PaulaCom
Path Finder

Morning All 

I am trying to work out how to use splunk spl to pick random names from a list

i have 1 field called 'displayName'. there are over 200 entries and i'd like to use Splunk to pick 5 random names 

 

appreciate help in this

Paula  

 

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

If your values are in a multi-value field, you can do something like this

| eval choice=mvindex(displayName, random()%200)

If the names are in separate events, you could do something like this

| eval id=random()%500
| sort 0 id
| head 5

View solution in original post

PaulaCom
Path Finder

thank  you the second option works for what i need

 

0 Karma

PaulaCom
Path Finder

i've looked at similar search online and have come up with this

| table "Display Name"
| eval "group" = (random() % 2) +1
| stats list("Display Name") as "Display Name" by "group"

this is returning random names in two groups
      

group display Name
1

joe blogs 5

joe blogs 2

joe blogs  6

2

joe blogs 7

joe blogs 8

joe blogs  12

 

Any ideas how i can set the number returning for each group? maybe using the limit function???

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval id=random()
| sort 0 id
| streamstats count as id
| eval group=((id - 1)%5) + 1
| stats list("Display Name") as "Display Name" by group

ITWhisperer
SplunkTrust
SplunkTrust

If your values are in a multi-value field, you can do something like this

| eval choice=mvindex(displayName, random()%200)

If the names are in separate events, you could do something like this

| eval id=random()%500
| sort 0 id
| head 5
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...