with the following search
index=core host="hostname" elementType=ET1 | stats values(randomField)
my output looks something like:
values(randomField)
117440512
117440515
117440516
117440517
117440519
117440520
117440521
117440530
117440531
...
if i download this in the csv format it will all all appear in 2 rows. I want to be able to have the values(randomField)
on the 1st row and then 1 row per each subsequent value (e.g. 117440512
on row 2, 117440515
on row 3 ).
How can i alter my search to achieve this?
similar question asked here
Is there any reason why you arent using the table
command with a dedup
following it?
Using values will force it to create a multi value field with distinct values which will give the output on one line.
Using table with dedup will give the unique output in individual rows
Is there any reason why you arent using the table
command with a dedup
following it?
Using values will force it to create a multi value field with distinct values which will give the output on one line.
Using table with dedup will give the unique output in individual rows
++
If all you want is to isolate the values of randomField
, then you simply need to pipe to table
index=core host="hostname" elementType=ET1 | table randomField
@ramdaspr tks ...| table randomField | dedup randomField
this worked for me.