For example:
:Report=99,10,99
In this case value 99
occurred twice in this field, so I need to pick this event and then create an alert. Please help in solving this issue
Give this a try (works on Splunk 6.2.0 and above)
your base search | eval temp=split(Report,",") | where mvcount(temp)>mvcount(mvdedup(temp)) | fields - temp
It dint give me any response