Below is sample field value
Response : UX 189000055 - RESPONSE1, BB 10437470 - RESPONSE1, AB 11123345 RESPONSE2
If I search for string "RESPONSE1", then it query should display result as 2
Like this:
... | eval count=mvcount(split(_raw, "RESPONSE1")) - 1
| stats sum(count) AS count
Hi gjjagadeesh,
let me understand: do you want to know how many times there is RESPONSE1, how many times RESPONSE2 and so on?
If yes, try something like this example:
| makeresults
| eval message="UX 189000055 - RESPONSE1, BB 10437470 - RESPONSE1, AB 11123345 - RESPONSE2"
| rex field=message max_match=0 "\w\w\s+\d+\s+-\s+(?<response>\w+)"
| mvexpand response
| stats count BY response
Bye.
Giuseppe
What is your question?
Need a query to achieve desired results