Answer by warren for Using splunk to plot table of key counts extracted from json string field

It appears your JSON has multivalue fields

Try using mvexpand first:

index=ndx sourcetype=srctp
| mvexpand queryParams
| stats count by queryParams
| rename queryParams as "Query Param"

from User warren – Stack Overflow https://stackoverflow.com/questions/64763178/using-splunk-to-plot-table-of-key-counts-extracted-from-json-string-field/64775415#64775415
via IFTTT