<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add new label or name next to value in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Add-new-label-or-name-next-to-value/m-p/312648#M4277</link>
    <description>&lt;P&gt;Thank you very much. your valued suggestion works for me .&lt;/P&gt;

&lt;P&gt;Much appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Apr 2017 18:44:11 GMT</pubDate>
    <dc:creator>harishnpandey</dc:creator>
    <dc:date>2017-04-07T18:44:11Z</dc:date>
    <item>
      <title>Add new label or name next to value</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Add-new-label-or-name-next-to-value/m-p/312645#M4274</link>
      <description>&lt;P&gt;index=myindex  FruitType="Apple" OR FruitType="Banana" AND  ( FaultCode="201")|stats count by FaultCode,FruitType&lt;/P&gt;

&lt;P&gt;Fault Code  FruitType   Count&lt;/P&gt;

&lt;P&gt;201                  Apple              2&lt;BR /&gt;
201                 Banana              3&lt;BR /&gt;
202                  Apple                 6                &lt;/P&gt;

&lt;P&gt;is there any way I can give meaningful name to Fault Code in adjacent column name as "FaultType" and display those FaulType next to each FaultCode such as:&lt;/P&gt;

&lt;P&gt;Fault Code   Fault Type FruitType   Count&lt;/P&gt;

&lt;P&gt;201               Small size             Apple              2&lt;BR /&gt;
201               Small size           Banana       3&lt;BR /&gt;
202                Decay                   Apple             6     &lt;/P&gt;

&lt;P&gt;Appreciate your feedback and suggestion on this.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Harry&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 19:36:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Add-new-label-or-name-next-to-value/m-p/312645#M4274</guid>
      <dc:creator>harishnpandey</dc:creator>
      <dc:date>2017-04-05T19:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: Add new label or name next to value</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Add-new-label-or-name-next-to-value/m-p/312646#M4275</link>
      <description>&lt;P&gt;Hi Harry&lt;/P&gt;

&lt;P&gt;The &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.3/Knowledge/Usefieldlookupstoaddinformationtoyourevents"&gt;documentation&lt;/A&gt; walks you through how to do this using what Splunk call lookups.&lt;/P&gt;

&lt;P&gt;Dave &lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 10:43:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Add-new-label-or-name-next-to-value/m-p/312646#M4275</guid>
      <dc:creator>davebrooking</dc:creator>
      <dc:date>2017-04-07T10:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: Add new label or name next to value</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Add-new-label-or-name-next-to-value/m-p/312647#M4276</link>
      <description>&lt;P&gt;you could create a lookup for each code and input it, as @davebrooking says in the comments. If there are only a few codes, you could create an eval statement. I wouldn't recommend that for a lot of codes, only because it could get very long, though you could put it in a macro and use it in other searches as well.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|eval FaultType=case(FaultCode="201","Small Size",FaultCode="202","Decay")
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.3/Knowledge/Definesearchmacros"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.3/Knowledge/Definesearchmacros&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 11:54:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Add-new-label-or-name-next-to-value/m-p/312647#M4276</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-04-07T11:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Add new label or name next to value</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Add-new-label-or-name-next-to-value/m-p/312648#M4277</link>
      <description>&lt;P&gt;Thank you very much. your valued suggestion works for me .&lt;/P&gt;

&lt;P&gt;Much appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 18:44:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Add-new-label-or-name-next-to-value/m-p/312648#M4277</guid>
      <dc:creator>harishnpandey</dc:creator>
      <dc:date>2017-04-07T18:44:11Z</dc:date>
    </item>
  </channel>
</rss>

