Splunk Search

How do you combine two different values from a single field in a chart?

dojiepreji
Path Finder

Suppose I have a chart that counts the number of tickets done by a particular branch and displays them by priority.

Branch     Priority 1     Priority 2     Priority 3
branch1          2             3            5
branch2          1             2            2
branch3          3             4            3

What I want to do is combine branches 1 and 2 like so,

Branch           Priority 1     Priority 2     Priority 2
branch1/branch2        3            5               7
branch 3               3            4               3

I've tried replace, but it only renames the value of a single branch, and does not combine them.

I've also considered the coalesce command, but I could only use it when combining values coming from two different fields, not values coming from a single field.

Can anybody please point me in the right direction?

0 Karma

woodcock
Esteemed Legend

You can add this to the bottom of your existing search:

| eval Branch = if(Branch=="branch1" OR Branch=="branch2", "branch1/branch2", Branch)
| stats sum(*) AS * BY Branch

But you might get better performance if you move the eval line to be the first pipe after your base search string so that you do not need the stats line at all.

0 Karma

mayurr98
Super Champion

Hi @dojiepreji

you can try something like this:

<query for the chart>
| replace branch2 with branch1 in Branch 
| stats  sum(Priority*) as Priority* by Branch 
|  replace branch1 WITH branch1/branch2 in Branch

let me know if this helps!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...