Alerting

How do I group similar values together?

srizan
Path Finder
source=*prod*
 | dedup SRV JAVAVER
 | stats count(SRV) by JAVAVER

This would generate report with all of the Java Versions.

I visualized using PieChart but I am only interested in seeing the chart with JAVAVER grouped as Java 18, Java 17 & Java19 instead of Java1801, Java1802, and so on.

Bascially, I want to group something like this only for the Pie Chart if possible:

JAVAVER=Java19* -> Java19
 JAVAVER=Java18* -> Java18
 JAVAVER=Java17* -> Java17
Tags (1)
0 Karma
1 Solution

anthonymelita
Contributor

You can use the substring function before your stats statement.
| eval JAVAVER=substr(JAVAVER,0,6)

View solution in original post

anthonymelita
Contributor

You can use the substring function before your stats statement.
| eval JAVAVER=substr(JAVAVER,0,6)

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...