Splunk Search

Combine table rows

lgroot
Explorer

Hi everyone,

I've got a question about a query i have made:

index=security-mijnssp "View rendered = /error.jspx" OR "Er is een fout opgetreden op de JSF pagina"  | rex "BSN=(?P<BSN>[^<]+) View" | rex "INFO  n.s.m.w.l(?P<INFO>[^<]+)"|rex "ERROR n.s.m.w.l(?P<ERROR>[^<]+)"|  table INFO,BSN, ERROR, _time

Is it possible to combine the results of this query in one row?
So that the INFO,BSN,ERROR and time are in one row?

alt text

0 Karma
1 Solution

somesoni2
Revered Legend

You would be able to combine this if they have a common field that can correlate them. From the example/screenshot, only common field I can see is _time, so my answer is based on _time, change the field if there are any other common fields.

Update
Actually BSN is the common field, so updating it to BSN

 index=security-mijnssp "View rendered = /error.jspx" OR "Er is een fout opgetreden op de JSF pagina"  | rex "BSN=(?P<BSN>[^<]+) View" | rex "INFO  n.s.m.w.l(?P<INFO>[^<]+)"|rex "ERROR n.s.m.w.l(?P<ERROR>[^<]+)"|  table INFO,BSN, ERROR, _time |stats values(*) as * by BSN

View solution in original post

0 Karma

somesoni2
Revered Legend

You would be able to combine this if they have a common field that can correlate them. From the example/screenshot, only common field I can see is _time, so my answer is based on _time, change the field if there are any other common fields.

Update
Actually BSN is the common field, so updating it to BSN

 index=security-mijnssp "View rendered = /error.jspx" OR "Er is een fout opgetreden op de JSF pagina"  | rex "BSN=(?P<BSN>[^<]+) View" | rex "INFO  n.s.m.w.l(?P<INFO>[^<]+)"|rex "ERROR n.s.m.w.l(?P<ERROR>[^<]+)"|  table INFO,BSN, ERROR, _time |stats values(*) as * by BSN
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...