how would I count the number of occurances of a character or symbol in an extracted field and display that as a seperate field?
for instance counting the number fields passed in a POST message? (delimited by 😃
i have looked at rex, mvcount and stats but so far havent come up with a solution to do it from a search.
Any ideas?
there's probably more than way to do it with the eval
command.
http://www.splunk.com/base/Documentation/latest/SearchReference/CommonEvalFunctions
Here's one, if you have a field called 'postPayload':
<your search> | eval numArgs = mvcount(split(postPayload,"="))-1
How about something like this:
sourcetype=access_combined | eval chars=mvcount(split(uri, "=")) - 1 | table uri, chars
there's probably more than way to do it with the eval
command.
http://www.splunk.com/base/Documentation/latest/SearchReference/CommonEvalFunctions
Here's one, if you have a field called 'postPayload':
<your search> | eval numArgs = mvcount(split(postPayload,"="))-1