I am new to splunk , can some one please help me on below case
my log looks like this
Name="ABCD"
Config Name="XYZ"
dates="2017-01-01,2017-01-02,2017-01-03,2017-01-05,2017-01-07"
missing_dates="2017-01-04,2017-01-06"
Msg="SUCCESS" or "FAIL"
I need to count number of missing dates and display in table table format with below headers only for SUCCESS Msg
Name Config count_of_missing_dates Msg
Assuming you already have the fields extracted, try this.
... | eval count_of_missing_dates = mvcount(split(missing_dates, ",")) | ...
Assuming you already have the fields extracted, try this.
... | eval count_of_missing_dates = mvcount(split(missing_dates, ",")) | ...
Or, to be more verbose...
your base search
| where Msg="SUCCESS"
| eval count_of_missing_dates = mvcount(split(missing_dates, ","))
| table Name Config count_of_missing_dates Msg
Thank you very much 🙂 it's worked