<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to show multiple values in one value in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536786#M36668</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to display two columns OPEN and Closed in a table .&lt;/P&gt;&lt;P&gt;I want to include Submitted,Fixed in OPEN column and Closed,Resolved in&amp;nbsp; Closed column.&lt;/P&gt;&lt;P&gt;Can you guide me on this.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jan 2021 05:25:01 GMT</pubDate>
    <dc:creator>aditsss</dc:creator>
    <dc:date>2021-01-22T05:25:01Z</dc:date>
    <item>
      <title>How to show multiple values in one value</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536742#M36655</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have one requirement:&lt;/P&gt;&lt;P&gt;I have one lookup where there is one column Case_Status. It has multiple values&amp;nbsp; for Case status:&lt;/P&gt;&lt;P&gt;Resolved&lt;/P&gt;&lt;P&gt;Closed- Resolved&lt;/P&gt;&lt;P&gt;Resolved - UpdateCase&lt;/P&gt;&lt;P&gt;Submitted&lt;/P&gt;&lt;P&gt;Pending&amp;nbsp;&lt;/P&gt;&lt;P&gt;Escalated&lt;/P&gt;&lt;P&gt;My requirement is I need only two values that is open and closed&lt;/P&gt;&lt;P&gt;I need to include Resolved submitted and pending in OPEN and Escalated, Resolved and Resolved Update Case in Closed.&lt;/P&gt;&lt;P&gt;How can I achieve this.&lt;/P&gt;&lt;P&gt;My current query:&lt;/P&gt;&lt;P&gt;|inputlookup Sdf.csv| table CaseStatus | dedup CaseStatus&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 20:03:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536742#M36655</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-01-21T20:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to show multiple values in one value</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536744#M36656</link>
      <description>&lt;P&gt;Hi You can try,&lt;BR /&gt;Something like |stats first(&lt;SPAN&gt;CaseStatus&lt;/SPAN&gt;) as&amp;nbsp;&lt;SPAN&gt;Case_Status&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;or&lt;BR /&gt;|stats min(&lt;SPAN&gt;CaseStatus&lt;/SPAN&gt;) as&amp;nbsp;&lt;SPAN&gt;Case_Status&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;even try |stats value(*) AS * by&amp;nbsp;&lt;SPAN&gt;CaseStatus if that help&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 20:15:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536744#M36656</guid>
      <dc:creator>bapun18</dc:creator>
      <dc:date>2021-01-21T20:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to show multiple values in one value</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536745#M36657</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/204073"&gt;@bapun18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I include my values in Two fields:&lt;/P&gt;&lt;P&gt;I want to create one field open and want to include submitted pending in OPEN and Rest in closed.&lt;/P&gt;&lt;P&gt;Can you guide me on that.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 20:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536745#M36657</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-01-21T20:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to show multiple values in one value</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536746#M36658</link>
      <description>&lt;P&gt;You could add a column to the lookup, but it might be easiest to map the status values using a case statement.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|inputlookup Sdf.csv
| fields CaseStatus 
| dedup CaseStatus
| eval CaseStatus=case(CaseStatus="Resolved" OR CaseStatus="Submitted" OR CaseStatus="Pending", "OPEN", CaseStatus="Escalated" OR CaseStatus="Closed- Resolved" OR CaseStatus="Resolved - UpdateCase", "Closed", 1==1,CaseStatus)
| table CaseStatus&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 21 Jan 2021 20:20:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536746#M36658</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-21T20:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to show multiple values in one value</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536753#M36661</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried like this:&lt;/P&gt;&lt;P&gt;|inputlookup mnr_rally_defects.csv| sort -rundatetime| dedup state| eval state=case(state="Submitted" OR state="Fixed" OR state="Open", "OPEN", state="Closed" "Closed", 1==1,state)|table rundatetime state&lt;/P&gt;&lt;P&gt;I am getting error as :&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Error in 'eval' command: The expression is malformed. Expected ).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 20:56:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536753#M36661</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-01-21T20:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to show multiple values in one value</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536782#M36666</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you guide me on this.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 05:10:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536782#M36666</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-01-22T05:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to show multiple values in one value</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536786#M36668</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to display two columns OPEN and Closed in a table .&lt;/P&gt;&lt;P&gt;I want to include Submitted,Fixed in OPEN column and Closed,Resolved in&amp;nbsp; Closed column.&lt;/P&gt;&lt;P&gt;Can you guide me on this.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 05:25:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536786#M36668</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-01-22T05:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to show multiple values in one value</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536800#M36671</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please guide me on this.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 08:46:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536800#M36671</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-01-22T08:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to show multiple values in one value</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536802#M36672</link>
      <description>&lt;P&gt;When using case end the brackets with&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;,true(), "exampleValue")&lt;BR /&gt;&lt;BR /&gt;as an option if none of your previous cases are True&lt;BR /&gt;&lt;BR /&gt;(I'm relatively new to Splunk so take my thoughts with a grain of salt)&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 09:36:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536802#M36672</guid>
      <dc:creator>FelixLeh</dc:creator>
      <dc:date>2021-01-22T09:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to show multiple values in one value</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536806#M36674</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You have missing comma, please try below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup mnr_rally_defects.csv 
| sort -rundatetime 
| dedup state 
| eval state=case(state="Submitted" OR state="Fixed" OR state="Open", "OPEN", state="Closed","Closed", 1==1,state) 
| table rundatetime state&lt;/LI-CODE&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 09:33:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536806#M36674</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-22T09:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to show multiple values in one value</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536810#M36675</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to merge three columns submitted,fixed and open as one column Open and closed and resolved as closed.All these columns contains numeric values.&lt;/P&gt;&lt;P&gt;Will the below query correct.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 09:54:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536810#M36675</guid>
      <dc:creator>aditsss</dc:creator>
      <dc:date>2021-01-22T09:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to show multiple values in one value</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536811#M36676</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225066"&gt;@aditsss&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The query is only missing resolved state, I added below. But I couldn't understand "All these columns contains numeric values". I think you meant about some other columns since state columns are string in your search. If you can post some sample data, we can have better recommendation.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| inputlookup mnr_rally_defects.csv 
| sort -rundatetime 
| dedup state 
| eval state=case(state="Submitted" OR state="Fixed" OR state="Open", "OPEN", state="Closed" OR state="Resolved","Closed", 1==1,state) 
| table rundatetime state&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 10:04:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-to-show-multiple-values-in-one-value/m-p/536811#M36676</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-22T10:04:38Z</dc:date>
    </item>
  </channel>
</rss>

