I am trying to create a bar chart from a field that could have 0 or multiple values delimited with ;
An example of the data is:
{"auditSource":"frontend","auditType":"Results","eventId":"4a99edaf-cc97-4e19-9146-1a2a4cb90856","tags":{"clientIP":""},"detail":{"successful":"false","errorCodes":"56004;56003"},"generatedAt":"2016-01-28T21:50:35.320Z"}
So I know that detail.errorCodes will give me the value '56004;56003', but I'm not sure how to separate these and create a bar chart from the result.
Would the following work for you?
| yoursearch
| eval code = split('detail.errorCodes', ";")
| mvexpand code
| stats count by code
Would the following work for you?
| yoursearch
| eval code = split('detail.errorCodes', ";")
| mvexpand code
| stats count by code
Hello, cheers for the answer. However it doesn't work. It says "'Field 'code' does not exist in the data."
It just returns all the events matching the search.
That's because i forgot the single quotes with the field name.
I've fixed my answer above. Please try again:
| yoursearch
| eval code = split('detail.errorCodes', ";")
| mvexpand code
| stats count by code
Awesome! works great, Thanks!