Splunk Search

using spl to pick random names from list

PaulaCom
Path Finder

Morning All 

I am trying to work out how to use splunk spl to pick random names from a list

i have 1 field called 'displayName'. there are over 200 entries and i'd like to use Splunk to pick 5 random names 

 

appreciate help in this

Paula  

 

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

If your values are in a multi-value field, you can do something like this

| eval choice=mvindex(displayName, random()%200)

If the names are in separate events, you could do something like this

| eval id=random()%500
| sort 0 id
| head 5

View solution in original post

PaulaCom
Path Finder

thank  you the second option works for what i need

 

0 Karma

PaulaCom
Path Finder

i've looked at similar search online and have come up with this

| table "Display Name"
| eval "group" = (random() % 2) +1
| stats list("Display Name") as "Display Name" by "group"

this is returning random names in two groups
      

group display Name
1

joe blogs 5

joe blogs 2

joe blogs  6

2

joe blogs 7

joe blogs 8

joe blogs  12

 

Any ideas how i can set the number returning for each group? maybe using the limit function???

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| eval id=random()
| sort 0 id
| streamstats count as id
| eval group=((id - 1)%5) + 1
| stats list("Display Name") as "Display Name" by group

ITWhisperer
SplunkTrust
SplunkTrust

If your values are in a multi-value field, you can do something like this

| eval choice=mvindex(displayName, random()%200)

If the names are in separate events, you could do something like this

| eval id=random()%500
| sort 0 id
| head 5
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...