All,
Weird search. How can I get a count of words in an event?
e.g.
_raw = "Hello world. Hello state. Hello France"
outputs -
Hello = 3
world = 1
state = 1
France = 1
Try this
... | rex max_match=0 "(?<words>\w+)" | mvexpand words | stats count by words
Try this
... | rex max_match=0 "(?<words>\w+)" | mvexpand words | stats count by words
How does max_match=0 work?
By default rex command will only get the first instance. max_match Controls the number of times the regex is matched. It will match all (max_match=0) instances put the values in a multivalue field.
http://docs.splunk.com/Documentation/Splunk/6.0.5/SearchReference/Rex