Splunk Search

How to create a table using dedup to show one entry for each application name and create a multivalue field?

stuart338
New Member

I have events that include an application name field and a uservalue field.

When i table the data by application and uservalue, i see each event individually thus meaning i get multiple pages of events with the same application name.

How can I have one entry for each application name and a multivalue field showing the uservalues?

EG: go from

application uservalue
app1            123456
app1            234567
app1            345678
app2            987654
app2            876543
app2            765432

and get :

application uservalue
app1          123456
              234567
              345678
app2          987654
              876543
              765432

It's probably something really easy, but I've stepped away from Splunk for awhile and forget even the easy stuff.

Thanks

0 Karma
1 Solution

dmaislin_splunk
Splunk Employee
Splunk Employee
source="Workbook1.csv" sourcetype="csv" | stats list(uservalue) as UserValue by application

alt text

View solution in original post

dmaislin_splunk
Splunk Employee
Splunk Employee
source="Workbook1.csv" sourcetype="csv" | stats list(uservalue) as UserValue by application

alt text

stuart338
New Member

See, i knew it was easy.. Thanks.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...