Splunk Search

How to create a table using dedup to show one entry for each application name and create a multivalue field?

stuart338
New Member

I have events that include an application name field and a uservalue field.

When i table the data by application and uservalue, i see each event individually thus meaning i get multiple pages of events with the same application name.

How can I have one entry for each application name and a multivalue field showing the uservalues?

EG: go from

application uservalue
app1            123456
app1            234567
app1            345678
app2            987654
app2            876543
app2            765432

and get :

application uservalue
app1          123456
              234567
              345678
app2          987654
              876543
              765432

It's probably something really easy, but I've stepped away from Splunk for awhile and forget even the easy stuff.

Thanks

0 Karma
1 Solution

dmaislin_splunk
Splunk Employee
Splunk Employee
source="Workbook1.csv" sourcetype="csv" | stats list(uservalue) as UserValue by application

alt text

View solution in original post

dmaislin_splunk
Splunk Employee
Splunk Employee
source="Workbook1.csv" sourcetype="csv" | stats list(uservalue) as UserValue by application

alt text

stuart338
New Member

See, i knew it was easy.. Thanks.

0 Karma
Get Updates on the Splunk Community!

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...