You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何编写Splunk查询统计stringIdList列表元素的出现次数?

Splunk查询:统计数组字段内元素的出现次数

针对日志格式:

index=foo stringIdList=["id1","id2","id2","id3","id3","id3"]

直接使用top命令只会统计整个stringIdList字段的出现次数,无法拆分数组内的元素。正确的查询需要先拆分数组、展开元素,再统计计数:

index=foo
| eval stringIdList=replace(stringIdList, "^\\[|\\]$", "")
| makemv delim="," stringIdList
| mvexpand stringIdList
| eval stringIdList=replace(stringIdList, "\"", "")
| stats count by stringIdList

步骤说明:

  • replace(stringIdList, "^\\[|\\]$", ""):移除数组首尾的方括号,将["id1","id2"]转换为"id1","id2"
  • makemv delim="," stringIdList:以逗号为分隔符,将处理后的字符串转换为多值字段
  • mvexpand stringIdList:把多值字段的每个元素拆分为单独的事件行
  • replace(stringIdList, "\"", ""):移除元素的双引号,得到纯净的ID值
  • stats count by stringIdList:按ID分组统计出现次数,生成包含元素和对应次数的表格

内容的提问来源于stack exchange,提问作者Akhil

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 01:43:10