Hi,
I have a json coming from CI with this template :
{"source":"1","sourcetype":"json","event":{"type":"build","id":"061","durartion":"48","run_id":"1","paths":["value1",".value2","value3"]}
the filed are listed in splunk as:
id, duration, sourcetype, paths{} and i can list all the values but my issue is i want to count paths{} (more then 11k values) I tried using mvcount as
| eval totalpaths = mvcount(paths) retuns nothing
| eval totalpaths = mvcount(paths{}) return 1
is there a way how i can return the number of total path ?
how i can list all paths ?
I tried using
| stats values(paths{}) as paths | stats count(eval(paths)) AS totalbazelpaths returns 378 while the actual value is above 11k.
when expanding paths{} field I can see all 11k paths.
what im doing wrong here?
thanks
... View more