Splunk Search

Why am I unable to combine multivalue fields in my search?

jagdeepgupta813
Explorer

HI,

I have a search in which I am interested in three fields:

index=my_computer sorucetype=asia_data message="Null_fields" | table item_id, country, count

My data has the same item id for multiple countries, say : Item1 for CHN,JPN. IND etc.
Also, it can occur multiple times for the same country.
There could be multiple hosts for the same country.

SO I want results in the format

ITEM_ID   Countries   HOST
Item1     CHN, JPN    Host1, host2

I tried using mvcombine, but it does not give the result as per my expectation.

0 Karma

javiergn
Super Champion

If I understand correctly your question:

index=my_computer sorucetype=asia_data message="Null_fields"
| stats values(country) as Countries, values(host) as host by item_id
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...