<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get single row output with fields from multiple events from multiple log files in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464982#M131015</link>
    <description>&lt;P&gt;My query is as below:&lt;BR /&gt;
index=e2etest OR index=dtix AND source IN (/opt/delphi/dtix/tomcat/logs/Messaging.log* , *NFAM.log) 2020021076664318 &lt;BR /&gt;
| table DELPHI_REQUEST.REQUEST.CID,DELPHI_REQUEST.REQUEST.COMMAND,DELPHI_RESPONSE.RESULTS.TRANID,DELPHI_REQUEST.CTLHDR.SYS_NAME,DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP,DELPHI_REQUEST.CTLHDR.TRANID,source&lt;BR /&gt;
| rename DELPHI_REQUEST.REQUEST.CID as "CKTID",DELPHI_REQUEST.REQUEST.COMMAND as "Command",DELPHI_RESPONSE.RESULTS.TRANID as "Resp_Tranid",DELPHI_REQUEST.CTLHDR.TRANID as "Req_Tranid",DELPHI_REQUEST.CTLHDR.SYS_NAME as "System",DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP as "Req Timestamp",DELPHI_REQUEST.REQUEST.SID as "Req_SessionId,DELPHI_RESPONSE.REQUEST.SID as "resp_SessionId,DELPHI_RESPONSE.RESULTS.ANALYSIS.TRBL_CODE as "Trouble Code"&lt;/P&gt;

&lt;P&gt;Click on below image URl for o/p of my search&lt;/P&gt;

&lt;P&gt;&lt;A href="https://drive.google.com/file/d/15R077UEyxoEaP2Z7d2YdeShfXzkA7jdI/view?usp=drivesdk" target="_blank"&gt;https://drive.google.com/file/d/15R077UEyxoEaP2Z7d2YdeShfXzkA7jdI/view?usp=drivesdk&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:05:49 GMT</pubDate>
    <dc:creator>poddraj</dc:creator>
    <dc:date>2020-09-30T04:05:49Z</dc:date>
    <item>
      <title>How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464975#M131008</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;My scenario is I have multiple request and response xmls which are basically my events in index for one circuit id. Basically, whenever I request with the circuit id from UI it will create a new transaction id for that particular hit which means logs will have multiple requestids for the same circuit id for 1 day.&lt;BR /&gt;
What I need is when I search with the circuit ID it should give me a table output showing all the different request ids along with their specific response fields in a single row.&lt;/P&gt;

&lt;P&gt;My challenge here is I am trying to show the fields from request &amp;amp; response xmls from multiple source files into a single row but it is returning multiple rows. Please help if there is any way to get this done.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 08:04:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464975#M131008</guid>
      <dc:creator>poddraj</dc:creator>
      <dc:date>2020-02-11T08:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464976#M131009</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I am adding more inputs for better understanding of my issue. Below are my request &amp;amp; reponse xml samples. I need a tabular output in a single row for 1 circuit id with highlighted fields from below request &amp;amp; response xmls.&lt;BR /&gt;
Kindly help as I am getting o/p in 2 separate rows where request xml fields in one row and response xml fields in other row. &lt;BR /&gt;
Note: APP_REQUEST.REQUEST.CID &amp;amp; APP_RESPONSE.REQUEST.CID will always have same value.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Request XML whose source = A
---------------------------------------
&amp;lt;APP _REQUEST&amp;gt;
    &amp;lt;CTLHDR&amp;gt;
        &amp;lt;DIPVER&amp;gt;5.0&amp;lt;/DIPVER&amp;gt;
        &amp;lt;DOMAIN&amp;gt;FTTP&amp;lt;/DOMAIN&amp;gt;
        &amp;lt;SVC_ID&amp;gt;|1077606440069375000|HEM&amp;lt;/SVC_ID&amp;gt;
         &amp;lt;SYS_ID&amp;gt;10-118-21.xx.com&amp;lt;/SYS_ID&amp;gt;
        &amp;lt;SVC_NAME&amp;gt;TEST&amp;lt;/SVC_NAME&amp;gt;
        &amp;lt;SYS_NAME&amp;gt;DTI_EXPRESS&amp;lt;/SYS_NAME&amp;gt;
        &amp;lt;DTIMEOUT&amp;gt;3&amp;lt;/DTIMEOUT&amp;gt;
        &amp;lt;ATTACHMENTS&amp;gt;Y&amp;lt;/ATTACHMENTS&amp;gt;
        &amp;lt;REQ_TIME_STAMP&amp;gt;2020-02-10T10:11:14Z&amp;lt;/REQ_TIME_STAMP&amp;gt;
        &amp;lt;TSTMODE&amp;gt;REAL&amp;lt;/TSTMODE&amp;gt;
    &amp;lt;/CTLHDR&amp;gt;
    &amp;lt;REQUEST&amp;gt;
        **&amp;lt;CID&amp;gt;12345&amp;lt;/CID&amp;gt;**
        &amp;lt;TSTCOND&amp;gt;S&amp;lt;/TSTCOND&amp;gt;
        &amp;lt;TR_TYPE&amp;gt;CCON&amp;lt;/TR_TYPE&amp;gt;
        &amp;lt;SVCTYPE&amp;gt;DATA&amp;lt;/SVCTYPE&amp;gt;
        **&amp;lt;COMMAND&amp;gt;GET_BHR_CFG&amp;lt;/COMMAND&amp;gt;
        &amp;lt;EMP_ID&amp;gt;97864&amp;lt;/EMP_ID&amp;gt;**
        &amp;lt;WK_TYPE&amp;gt;M&amp;lt;/WK_TYPE&amp;gt;
        &amp;lt;JOB_TYPE&amp;gt;M&amp;lt;/JOB_TYPE&amp;gt;
        &amp;lt;REQUIRED&amp;gt;
            &amp;lt;SVCTYPE&amp;gt;DATA&amp;lt;/SVCTYPE&amp;gt;
            &amp;lt;COMMAND&amp;gt;GET_BHR_CFG&amp;lt;/COMMAND&amp;gt;
            &amp;lt;EMP_ID&amp;gt;97864&amp;lt;/EMP_ID&amp;gt;
            &amp;lt;WK_TYPE&amp;gt;M&amp;lt;/WK_TYPE&amp;gt;
            &amp;lt;JOB_TYPE&amp;gt;M&amp;lt;/JOB_TYPE&amp;gt;
        &amp;lt;/REQUIRED&amp;gt;
        &amp;lt;ATTRIBUTES&amp;gt;
            &amp;lt;NUM_ATTRS&amp;gt;0&amp;lt;/NUM_ATTRS&amp;gt;
        &amp;lt;/ATTRIBUTES&amp;gt;
        &amp;lt;SID&amp;gt;A76664317&amp;lt;/SID&amp;gt;
    &amp;lt;/REQUEST&amp;gt;
&amp;lt;/APP_REQUEST&amp;gt;

Response XMLwhose source = B
---------------------------------
&amp;lt;APP_RESPONSE&amp;gt;
    &amp;lt;CTLHDR&amp;gt;
        &amp;lt;DIPVER&amp;gt;5.0&amp;lt;/DIPVER&amp;gt;
        &amp;lt;DOMAIN&amp;gt;FTTP&amp;lt;/DOMAIN&amp;gt;
        &amp;lt;SVC_ID&amp;gt;|1074764670547209000|HEM&amp;lt;/SVC_ID&amp;gt;
        &amp;lt;SYS_ID&amp;gt;10-118-21.xx.com&amp;lt;/SYS_ID&amp;gt;
        &amp;lt;SVC_NAME&amp;gt;TEST&amp;lt;/SVC_NAME&amp;gt;
        &amp;lt;SYS_NAME&amp;gt;DTI_EXPRESS&amp;lt;/SYS_NAME&amp;gt;
        &amp;lt;DTIMEOUT&amp;gt;3&amp;lt;/DTIMEOUT&amp;gt;
        &amp;lt;ATTACHMENTS&amp;gt;Y&amp;lt;/ATTACHMENTS&amp;gt;
        &amp;lt;REQ_TIME_STAMP&amp;gt;2020-02-10T09:23:52Z&amp;lt;/REQ_TIME_STAMP&amp;gt;
        &amp;lt;TSTMODE&amp;gt;REAL&amp;lt;/TSTMODE&amp;gt;
    &amp;lt;/CTLHDR&amp;gt;
    &amp;lt;REQUEST&amp;gt;
        &amp;lt;CID&amp;gt;12345&amp;lt;/CID&amp;gt;
        &amp;lt;TSTCOND&amp;gt;S&amp;lt;/TSTCOND&amp;gt;
        **&amp;lt;TR_TYPE&amp;gt;CCON&amp;lt;/TR_TYPE&amp;gt;**
        &amp;lt;SVCTYPE&amp;gt;DATA&amp;lt;/SVCTYPE&amp;gt;
        &amp;lt;COMMAND&amp;gt;GET_BHR_CFG&amp;lt;/COMMAND&amp;gt;
        &amp;lt;EMP_ID&amp;gt; 97864&amp;lt;/EMP_ID&amp;gt;
        &amp;lt;WK_TYPE&amp;gt;M&amp;lt;/WK_TYPE&amp;gt;
        &amp;lt;JOB_TYPE&amp;gt;M&amp;lt;/JOB_TYPE&amp;gt;
        &amp;lt;NETYPE&amp;gt;BHR&amp;lt;/NETYPE&amp;gt;
        &amp;lt;REQUIRED&amp;gt;
            &amp;lt;SVCTYPE&amp;gt;DATA&amp;lt;/SVCTYPE&amp;gt;
            &amp;lt;COMMAND&amp;gt;GET_BHR_CFG&amp;lt;/COMMAND&amp;gt;
            &amp;lt;EMP_ID&amp;gt;96864&amp;lt;/EMP_ID&amp;gt;
            &amp;lt;WK_TYPE&amp;gt;M&amp;lt;/WK_TYPE&amp;gt;
            &amp;lt;JOB_TYPE&amp;gt;M&amp;lt;/JOB_TYPE&amp;gt;
        &amp;lt;/REQUIRED&amp;gt;
        &amp;lt;ATTRIBUTES&amp;gt;
            &amp;lt;NUM_ATTRS&amp;gt;0&amp;lt;/NUM_ATTRS&amp;gt;
        &amp;lt;/ATTRIBUTES&amp;gt;
        &amp;lt;SID&amp;gt;A76555190&amp;lt;/SID&amp;gt;
    &amp;lt;/REQUEST&amp;gt;
 &amp;lt;RESULTS&amp;gt;
  &amp;lt;RETC&amp;gt;0000&amp;lt;/RETC&amp;gt;
  &amp;lt;RSTYPE&amp;gt;C&amp;lt;/RSTYPE&amp;gt;
  **&amp;lt;INFOMSG&amp;gt;Request Successful&amp;lt;/INFOMSG&amp;gt;**
  &amp;lt;TIME_SENT&amp;gt;2017-12-13T15:17:07Z&amp;lt;/TIME_SENT&amp;gt;
  **&amp;lt;TRANID&amp;gt;2017121376436144&amp;lt;/TRANID&amp;gt;**
  &amp;lt;SID&amp;gt;A76436143&amp;lt;/SID&amp;gt;
  &amp;lt;NUM_ANA&amp;gt;1&amp;lt;/NUM_ANA&amp;gt;
  &amp;lt;ANALYSIS&amp;gt;
   &amp;lt;NEID&amp;gt;G131500234&amp;lt;/NEID&amp;gt;
   &amp;lt;NETYPE&amp;gt;BHR&amp;lt;/NETYPE&amp;gt;
   **&amp;lt;DC&amp;gt;TOK&amp;lt;/DC&amp;gt;**
   &amp;lt;DC_SSUM&amp;gt;Retrieve succees&amp;lt;/DC_SSUM&amp;gt;
   &amp;lt;CKTDM&amp;gt;FTTP&amp;lt;/CKTDM&amp;gt;
   &amp;lt;TRBL_LOCATION_CODE&amp;gt;G1A00234&amp;lt;/TRBL_LOCATION_CODE&amp;gt;
   **&amp;lt;TRBL_CODE&amp;gt;TSDELTOK&amp;lt;/TRBL_CODE&amp;gt;**
   &amp;lt;TRBL_LAYER&amp;gt;1&amp;lt;/TRBL_LAYER&amp;gt;
   &amp;lt;EXPLANATION&amp;gt;Retrieve success&amp;lt;/EXPLANATION&amp;gt;
  &amp;lt;/ANALYSIS&amp;gt;
&amp;lt;/APP_RESPONSE&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:05:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464976#M131009</guid>
      <dc:creator>poddraj</dc:creator>
      <dc:date>2020-09-30T04:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464977#M131010</link>
      <description>&lt;P&gt;Please share the search you have currently, and, if possible some sample data&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 15:32:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464977#M131010</guid>
      <dc:creator>wmyersas</dc:creator>
      <dc:date>2020-02-11T15:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464978#M131011</link>
      <description>&lt;P&gt;Hi wmyersas,&lt;/P&gt;

&lt;P&gt;Please find my query below :&lt;/P&gt;

&lt;P&gt;index=e2etest OR index=dtix AND source IN (/opt/delphi/dtix/tomcat/logs/Messaging.log* , *NFAM.log) 2020021076664318&lt;BR /&gt;
| table DELPHI_REQUEST.REQUEST.CID,DELPHI_REQUEST.REQUEST.COMMAND,DELPHI_RESPONSE.RESULTS.TRANID,DELPHI_REQUEST.CTLHDR.SYS_NAME,DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP,DELPHI_REQUEST.CTLHDR.TRANID,DELPHI_RESPONSE.RESULTS.ANALYSIS.TRBL_CODE,source&lt;BR /&gt;
| rename DELPHI_REQUEST.REQUEST.CID as "CKTID",DELPHI_REQUEST.REQUEST.COMMAND as "Command",DELPHI_RESPONSE.RESULTS.TRANID as "Resp_Tranid",DELPHI_REQUEST.CTLHDR.TRANID as "Req_Tranid",DELPHI_REQUEST.CTLHDR.SYS_NAME as "System",DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP as "Req Timestamp",DELPHI_REQUEST.REQUEST.SID as "Req_SessionId,DELPHI_RESPONSE.REQUEST.SID as "resp_SessionId,DELPHI_RESPONSE.RESULTS.ANALYSIS.TRBL_CODE as "Trouble Code"&lt;/P&gt;

&lt;P&gt;Fields are from 2 sources and from 2 different events (1 event from request xml and other event from response xml) but are related to 1 circuit id.&lt;BR /&gt;
I need songle row ouptut with all those fields&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:05:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464978#M131011</guid>
      <dc:creator>poddraj</dc:creator>
      <dc:date>2020-09-30T04:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464979#M131012</link>
      <description>&lt;P&gt;depending how your search works currently and/or what the current multi-row results look like, you could maybe use chart of xyseries.&lt;/P&gt;

&lt;P&gt;So if you're currently using stats to format the data already, maybe use chart instead, e.g&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | chart latest(result) over circuit_id by request_id
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or if you already have a table with fields of circuit_id, request_id and result, then maybe use xyseries to reformat it to a chart layout.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | xyseries circuit_id, request_id, result
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Without seeing the search...not sure if those will help, but worth mentioning i think.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:05:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464979#M131012</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2020-09-30T04:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464980#M131013</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;index=e2etest OR index=dtix AND source IN (/opt/delphi/dtix/tomcat/logs/Messaging.log* , *NFAM.log) 2020021076664318
| eval sessions = 1
| table DELPHI_REQUEST.REQUEST.CID,DELPHI_REQUEST.REQUEST.COMMAND,DELPHI_RESPONSE.RESULTS.TRANID,DELPHI_REQUEST.CTLHDR.SYS_NAME,DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP,DELPHI_REQUEST.CTLHDR.TRANID,source, sessions
| stats list(*) as * by sessions
| table DELPHI_REQUEST.REQUEST.CID,DELPHI_REQUEST.REQUEST.COMMAND,DELPHI_RESPONSE.RESULTS.TRANID,DELPHI_REQUEST.CTLHDR.SYS_NAME,DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP,DELPHI_REQUEST.CTLHDR.TRANID,source
| rename DELPHI_REQUEST.REQUEST.CID as "CKTID",DELPHI_REQUEST.REQUEST.COMMAND as "Command",DELPHI_RESPONSE.RESULTS.TRANID as "Resp_Tranid",DELPHI_REQUEST.CTLHDR.TRANID as "Req_Tranid",DELPHI_REQUEST.CTLHDR.SYS_NAME as "System",DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP as "Req Timestamp",DELPHI_REQUEST.REQUEST.SID as "Req_SessionId,DELPHI_RESPONSE.REQUEST.SID as "resp_SessionId,DELPHI_RESPONSE.RESULTS.ANALYSIS.TRBL_CODE as "Trouble Code"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;H2&gt;To marge different fields, create a key and use &lt;CODE&gt;stats&lt;/CODE&gt; .   &lt;/H2&gt;

&lt;P&gt;previous answer:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults
| eval _raw="&amp;lt;APP_REQUEST&amp;gt;
     &amp;lt;CTLHDR&amp;gt;
         &amp;lt;DIPVER&amp;gt;5.0&amp;lt;/DIPVER&amp;gt;
         &amp;lt;DOMAIN&amp;gt;FTTP&amp;lt;/DOMAIN&amp;gt;
         &amp;lt;SVC_ID&amp;gt;|1077606440069375000|HEM&amp;lt;/SVC_ID&amp;gt;
          &amp;lt;SYS_ID&amp;gt;10-118-21.xx.com&amp;lt;/SYS_ID&amp;gt;
         &amp;lt;SVC_NAME&amp;gt;TEST&amp;lt;/SVC_NAME&amp;gt;
         &amp;lt;SYS_NAME&amp;gt;DTI_EXPRESS&amp;lt;/SYS_NAME&amp;gt;
         &amp;lt;DTIMEOUT&amp;gt;3&amp;lt;/DTIMEOUT&amp;gt;
         &amp;lt;ATTACHMENTS&amp;gt;Y&amp;lt;/ATTACHMENTS&amp;gt;
         &amp;lt;REQ_TIME_STAMP&amp;gt;2020-02-10T10:11:14Z&amp;lt;/REQ_TIME_STAMP&amp;gt;
         &amp;lt;TSTMODE&amp;gt;REAL&amp;lt;/TSTMODE&amp;gt;
     &amp;lt;/CTLHDR&amp;gt;
     &amp;lt;REQUEST&amp;gt;
         **&amp;lt;CID&amp;gt;12345&amp;lt;/CID&amp;gt;**
         &amp;lt;TSTCOND&amp;gt;S&amp;lt;/TSTCOND&amp;gt;
         &amp;lt;TR_TYPE&amp;gt;CCON&amp;lt;/TR_TYPE&amp;gt;
         &amp;lt;SVCTYPE&amp;gt;DATA&amp;lt;/SVCTYPE&amp;gt;
         **&amp;lt;COMMAND&amp;gt;GET_BHR_CFG&amp;lt;/COMMAND&amp;gt;
         &amp;lt;EMP_ID&amp;gt;97864&amp;lt;/EMP_ID&amp;gt;**
         &amp;lt;WK_TYPE&amp;gt;M&amp;lt;/WK_TYPE&amp;gt;
         &amp;lt;JOB_TYPE&amp;gt;M&amp;lt;/JOB_TYPE&amp;gt;
         &amp;lt;REQUIRED&amp;gt;
             &amp;lt;SVCTYPE&amp;gt;DATA&amp;lt;/SVCTYPE&amp;gt;
             &amp;lt;COMMAND&amp;gt;GET_BHR_CFG&amp;lt;/COMMAND&amp;gt;
             &amp;lt;EMP_ID&amp;gt;97864&amp;lt;/EMP_ID&amp;gt;
             &amp;lt;WK_TYPE&amp;gt;M&amp;lt;/WK_TYPE&amp;gt;
             &amp;lt;JOB_TYPE&amp;gt;M&amp;lt;/JOB_TYPE&amp;gt;
         &amp;lt;/REQUIRED&amp;gt;
         &amp;lt;ATTRIBUTES&amp;gt;
             &amp;lt;NUM_ATTRS&amp;gt;0&amp;lt;/NUM_ATTRS&amp;gt;
         &amp;lt;/ATTRIBUTES&amp;gt;
         &amp;lt;SID&amp;gt;A76664317&amp;lt;/SID&amp;gt;
     &amp;lt;/REQUEST&amp;gt;
 &amp;lt;/APP_REQUEST&amp;gt;
#
 &amp;lt;APP_RESPONSE&amp;gt;
     &amp;lt;CTLHDR&amp;gt;
         &amp;lt;DIPVER&amp;gt;5.0&amp;lt;/DIPVER&amp;gt;
         &amp;lt;DOMAIN&amp;gt;FTTP&amp;lt;/DOMAIN&amp;gt;
         &amp;lt;SVC_ID&amp;gt;|1074764670547209000|HEM&amp;lt;/SVC_ID&amp;gt;
         &amp;lt;SYS_ID&amp;gt;10-118-21.xx.com&amp;lt;/SYS_ID&amp;gt;
         &amp;lt;SVC_NAME&amp;gt;TEST&amp;lt;/SVC_NAME&amp;gt;
         &amp;lt;SYS_NAME&amp;gt;DTI_EXPRESS&amp;lt;/SYS_NAME&amp;gt;
         &amp;lt;DTIMEOUT&amp;gt;3&amp;lt;/DTIMEOUT&amp;gt;
         &amp;lt;ATTACHMENTS&amp;gt;Y&amp;lt;/ATTACHMENTS&amp;gt;
         &amp;lt;REQ_TIME_STAMP&amp;gt;2020-02-10T09:23:52Z&amp;lt;/REQ_TIME_STAMP&amp;gt;
         &amp;lt;TSTMODE&amp;gt;REAL&amp;lt;/TSTMODE&amp;gt;
     &amp;lt;/CTLHDR&amp;gt;
     &amp;lt;REQUEST&amp;gt;
         &amp;lt;CID&amp;gt;12345&amp;lt;/CID&amp;gt;
         &amp;lt;TSTCOND&amp;gt;S&amp;lt;/TSTCOND&amp;gt;
         **&amp;lt;TR_TYPE&amp;gt;CCON&amp;lt;/TR_TYPE&amp;gt;**
         &amp;lt;SVCTYPE&amp;gt;DATA&amp;lt;/SVCTYPE&amp;gt;
         &amp;lt;COMMAND&amp;gt;GET_BHR_CFG&amp;lt;/COMMAND&amp;gt;
         &amp;lt;EMP_ID&amp;gt; 97864&amp;lt;/EMP_ID&amp;gt;
         &amp;lt;WK_TYPE&amp;gt;M&amp;lt;/WK_TYPE&amp;gt;
         &amp;lt;JOB_TYPE&amp;gt;M&amp;lt;/JOB_TYPE&amp;gt;
         &amp;lt;NETYPE&amp;gt;BHR&amp;lt;/NETYPE&amp;gt;
         &amp;lt;REQUIRED&amp;gt;
             &amp;lt;SVCTYPE&amp;gt;DATA&amp;lt;/SVCTYPE&amp;gt;
             &amp;lt;COMMAND&amp;gt;GET_BHR_CFG&amp;lt;/COMMAND&amp;gt;
             &amp;lt;EMP_ID&amp;gt;96864&amp;lt;/EMP_ID&amp;gt;
             &amp;lt;WK_TYPE&amp;gt;M&amp;lt;/WK_TYPE&amp;gt;
             &amp;lt;JOB_TYPE&amp;gt;M&amp;lt;/JOB_TYPE&amp;gt;
         &amp;lt;/REQUIRED&amp;gt;
         &amp;lt;ATTRIBUTES&amp;gt;
             &amp;lt;NUM_ATTRS&amp;gt;0&amp;lt;/NUM_ATTRS&amp;gt;
         &amp;lt;/ATTRIBUTES&amp;gt;
         &amp;lt;SID&amp;gt;A76555190&amp;lt;/SID&amp;gt;
     &amp;lt;/REQUEST&amp;gt;
  &amp;lt;RESULTS&amp;gt;
   &amp;lt;RETC&amp;gt;0000&amp;lt;/RETC&amp;gt;
   &amp;lt;RSTYPE&amp;gt;C&amp;lt;/RSTYPE&amp;gt;
   **&amp;lt;INFOMSG&amp;gt;Request Successful&amp;lt;/INFOMSG&amp;gt;**
   &amp;lt;TIME_SENT&amp;gt;2017-12-13T15:17:07Z&amp;lt;/TIME_SENT&amp;gt;
   **&amp;lt;TRANID&amp;gt;2017121376436144&amp;lt;/TRANID&amp;gt;**
   &amp;lt;SID&amp;gt;A76436143&amp;lt;/SID&amp;gt;
   &amp;lt;NUM_ANA&amp;gt;1&amp;lt;/NUM_ANA&amp;gt;
   &amp;lt;ANALYSIS&amp;gt;
    &amp;lt;NEID&amp;gt;G131500234&amp;lt;/NEID&amp;gt;
    &amp;lt;NETYPE&amp;gt;BHR&amp;lt;/NETYPE&amp;gt;
    **&amp;lt;DC&amp;gt;TOK&amp;lt;/DC&amp;gt;**
    &amp;lt;DC_SSUM&amp;gt;Retrieve succees&amp;lt;/DC_SSUM&amp;gt;
    &amp;lt;CKTDM&amp;gt;FTTP&amp;lt;/CKTDM&amp;gt;
    &amp;lt;TRBL_LOCATION_CODE&amp;gt;G1A00234&amp;lt;/TRBL_LOCATION_CODE&amp;gt;
    **&amp;lt;TRBL_CODE&amp;gt;TSDELTOK&amp;lt;/TRBL_CODE&amp;gt;**
    &amp;lt;TRBL_LAYER&amp;gt;1&amp;lt;/TRBL_LAYER&amp;gt;
    &amp;lt;EXPLANATION&amp;gt;Retrieve success&amp;lt;/EXPLANATION&amp;gt;
   &amp;lt;/ANALYSIS&amp;gt;
 &amp;lt;/APP_RESPONSE&amp;gt;"
 | makemv delim="#" _raw
| stats count by _raw
`comment("this is your sample, from here, the logic")`
| spath
| stats values(*) as *
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 12 Feb 2020 11:34:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464980#M131013</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-02-12T11:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464981#M131014</link>
      <description>&lt;P&gt;The query I am using is as below:&lt;/P&gt;

&lt;P&gt;index=e2etest OR index=dtix AND source IN (/opt/delphi/dtix/tomcat/logs/Messaging.log* , *NFAM.log) 2020021076664318 &lt;BR /&gt;
| table DELPHI_REQUEST.REQUEST.CID,DELPHI_REQUEST.REQUEST.COMMAND,DELPHI_RESPONSE.RESULTS.TRANID,DELPHI_REQUEST.CTLHDR.SYS_NAME,DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP,DELPHI_REQUEST.CTLHDR.TRANID,source&lt;BR /&gt;
| rename DELPHI_REQUEST.REQUEST.CID as "CKTID",DELPHI_REQUEST.REQUEST.COMMAND as "Command",DELPHI_RESPONSE.RESULTS.TRANID as "Resp_Tranid",DELPHI_REQUEST.CTLHDR.TRANID as "Req_Tranid",DELPHI_REQUEST.CTLHDR.SYS_NAME as "System",DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP as "Req Timestamp",DELPHI_REQUEST.REQUEST.SID as "Req_SessionId,DELPHI_RESPONSE.REQUEST.SID as "resp_SessionId,DELPHI_RESPONSE.RESULTS.ANALYSIS.TRBL_CODE as "Trouble Code"&lt;/P&gt;

&lt;P&gt;but it is giving me multiple rows of same transaction id&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:05:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464981#M131014</guid>
      <dc:creator>poddraj</dc:creator>
      <dc:date>2020-09-30T04:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464982#M131015</link>
      <description>&lt;P&gt;My query is as below:&lt;BR /&gt;
index=e2etest OR index=dtix AND source IN (/opt/delphi/dtix/tomcat/logs/Messaging.log* , *NFAM.log) 2020021076664318 &lt;BR /&gt;
| table DELPHI_REQUEST.REQUEST.CID,DELPHI_REQUEST.REQUEST.COMMAND,DELPHI_RESPONSE.RESULTS.TRANID,DELPHI_REQUEST.CTLHDR.SYS_NAME,DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP,DELPHI_REQUEST.CTLHDR.TRANID,source&lt;BR /&gt;
| rename DELPHI_REQUEST.REQUEST.CID as "CKTID",DELPHI_REQUEST.REQUEST.COMMAND as "Command",DELPHI_RESPONSE.RESULTS.TRANID as "Resp_Tranid",DELPHI_REQUEST.CTLHDR.TRANID as "Req_Tranid",DELPHI_REQUEST.CTLHDR.SYS_NAME as "System",DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP as "Req Timestamp",DELPHI_REQUEST.REQUEST.SID as "Req_SessionId,DELPHI_RESPONSE.REQUEST.SID as "resp_SessionId,DELPHI_RESPONSE.RESULTS.ANALYSIS.TRBL_CODE as "Trouble Code"&lt;/P&gt;

&lt;P&gt;Click on below image URl for o/p of my search&lt;/P&gt;

&lt;P&gt;&lt;A href="https://drive.google.com/file/d/15R077UEyxoEaP2Z7d2YdeShfXzkA7jdI/view?usp=drivesdk" target="_blank"&gt;https://drive.google.com/file/d/15R077UEyxoEaP2Z7d2YdeShfXzkA7jdI/view?usp=drivesdk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:05:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464982#M131015</guid>
      <dc:creator>poddraj</dc:creator>
      <dc:date>2020-09-30T04:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464983#M131016</link>
      <description>&lt;P&gt;HI to4kawa,&lt;/P&gt;

&lt;P&gt;Thanks for your reply, I have used your query which is using eval sessions=1, but that query is still it giving me multiple rows like below&lt;/P&gt;

&lt;P&gt;Query:&lt;BR /&gt;
index=fios OR index=dtix AND source IN (/opt/delphi/dtix/tomcat/logs/Messaging.log*, *NFAM.log ) "DELPHI_REQUEST.CTLHDR.DOMAIN"=FTTP OR "DELPHI_RESPONSE.CTLHDR.DOMAIN"=FTTP 84/KQXA/134861/VZVA&lt;BR /&gt;
| eval sessions=1&lt;BR /&gt;
| stats  list(DELPHI_REQUEST.REQUEST.CID) as CKTID list(DELPHI_RESPONSE.RESULTS.TRANID) as "Tranid" list(DELPHI_REQUEST.CTLHDR.TRANID) as Req_Tranid list(DELPHI_REQUEST.REQUEST.COMMAND) as Command list(DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP) as TimeStamp list(DELPHI_RESPONSE.RESULTS.ANALYSIS.TRBL_CODE) as TroubleCode  by sessions&lt;/P&gt;

&lt;P&gt;O/P:&lt;BR /&gt;
84/KQXA/VZVA 2020020576000004 2020020576000004 GET_TOPOLOGY 2020-02-05T07:01:11Z TSDELRVW&lt;BR /&gt;
84/KQXA/VZVA 2020020576000004                                     GET_TOPOLOGY 2020-02-05T07:01:11Z TSDELRVW&lt;BR /&gt;
84/KQXA/VZVA                                                                          GET_TOPOLOGY 2020-02-05T07:01:11Z TSDELRVW&lt;BR /&gt;
Actually above query will give me 6 raw events (i.e. 6 xmls) from 2 source files. I need only 1 row o/p i.e. only 1st row in above o/p&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:06:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464983#M131016</guid>
      <dc:creator>poddraj</dc:creator>
      <dc:date>2020-09-30T04:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464984#M131017</link>
      <description>&lt;P&gt;you seem to be tabling out a lot of fields.  Can you let us know what the fields/headers would be for the ideal "one row" of data you're looking to get to?  &lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 13:44:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464984#M131017</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2020-02-13T13:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464985#M131018</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;index=fios OR index=dtix AND source IN (/opt/delphi/dtix/tomcat/logs/Messaging.log*, *NFAM.log ) "DELPHI_REQUEST.CTLHDR.DOMAIN"=FTTP OR "DELPHI_RESPONSE.CTLHDR.DOMAIN"=FTTP 84/KQXA/134861/VZVA
| eval sessions=1
| stats list(DELPHI_REQUEST.REQUEST.CID) as CKTID list(DELPHI_RESPONSE.RESULTS.TRANID) as "Tranid" list(DELPHI_REQUEST.CTLHDR.TRANID) as Req_Tranid list(DELPHI_REQUEST.REQUEST.COMMAND) as Command list(DELPHI_REQUEST.CTLHDR.REQ_TIME_STAMP) as TimeStamp list(DELPHI_RESPONSE.RESULTS.ANALYSIS.TRBL_CODE) as TroubleCode by sessions
| dedup sessions
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 13 Feb 2020 13:50:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464985#M131018</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-02-13T13:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464986#M131019</link>
      <description>&lt;P&gt;Hi maciep,&lt;BR /&gt;
My idle o/p is as below with only 6 columns and the query I ran for getting it is:&lt;/P&gt;

&lt;P&gt;index=dtix  "CID"=82/KQXA/683013/VZNY&lt;BR /&gt;
| eval CKTID_TN=coalesce(DELPHI_RESPONSE.REQUEST.CID,DELPHI_RESPONSE.REQUEST.TN)&lt;BR /&gt;
| table CID, CKTID_TN TRANID, COMMAND, REQ_TIME_STAMP, TRBL_CODE, DC.&lt;BR /&gt;
Note: CKTID_TN value is not coming up not sure why my coalesce is not working which should ideally return same value CID column&lt;/P&gt;

&lt;P&gt;CID TRANID COMMANDREQ_TIME_STAMPTRBL_CODEDC&lt;/P&gt;

&lt;P&gt;82/KQXA/683013/VZNY   2020021376014711 GET_BHR_CFG 2020-02-13T03:21:59Z TSDELTOK TOK &lt;BR /&gt;
82/KQXA/683013/VZNY   2020021076664318 GET_BHR_CFG 2020-02-10T10:11:14Z TSDELTOK TOK &lt;BR /&gt;
82/KQXA/683013/VZNY   2017121376436144 GET_BHR_CFG 2020-02-10T09:23:52Z TSDELTOK TOK &lt;BR /&gt;
82/KQXA/683013/VZNY   2020021076000001 GET_BHR_CFG 2020-02-10T07:11:55Z TSDELTOK TOK &lt;/P&gt;

&lt;P&gt;Here I am using all the fields from reponse xml of circuit id and hence I got in 1 single row but when I try to add few fields from request xml then it is creating 2 rows for same cktid where 1 row is showing the fields from request xml and other row is showing values from response xmls&lt;/P&gt;

&lt;P&gt;Even I tried to join those two indexes with belwo join query still I am getting duplicate rows may be because of same request xmls being available in both the indexes?&lt;/P&gt;

&lt;P&gt;index = dtix source=/opt/delphi/dtix/tomcat/logs/Messaging.log* 76/KQXA/266281/VZNY&lt;BR /&gt;
 | join type=left CID [search index = fios source=*NFAM.log 76/KQXA/266281/VZNY&lt;BR /&gt;
 ] | table CID, COMMAND, TRANID,REQ_TIME_STAMP,TRANID, TRBL_CODE, DC&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:12:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464986#M131019</guid>
      <dc:creator>poddraj</dc:creator>
      <dc:date>2020-09-30T04:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464987#M131020</link>
      <description>&lt;P&gt;Thanks for your reply to4kawa.&lt;/P&gt;

&lt;P&gt;I tried above query I am getting results but have below questions:&lt;/P&gt;

&lt;P&gt;1.It is not listing the columns in relation to each other.&lt;BR /&gt;&lt;BR /&gt;
example:&lt;BR /&gt;
Col : Value&lt;BR /&gt;
Tranid:123&lt;BR /&gt;
Command:test&lt;BR /&gt;
Circuitid:ABC&lt;/P&gt;

&lt;P&gt;As per logs I have few more tranids under same ABC ckt but those are not getting shown in separate rows however, those are listed in the output but not against the same circuit id or command. Basically the ordering is not correctly showing in the output&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;I tried to use sort command on top of the query but it is not working&lt;/LI&gt;
&lt;LI&gt;When I try to export it is not exporting as rows but it is exporting in to single row with entire data. How to export it as normal excel&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 14 Feb 2020 11:07:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464987#M131020</guid>
      <dc:creator>poddraj</dc:creator>
      <dc:date>2020-02-14T11:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464988#M131021</link>
      <description>&lt;P&gt;When you used session in your query and the field condition was not provided by you, so I used it as is.&lt;/P&gt;

&lt;P&gt;O/P:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;84/KQXA/VZVA 2020020576000004 2020020576000004 GET_TOPOLOGY 2020-02-05T07:01:11Z TSDELRVW
84/KQXA/VZVA 2020020576000004 GET_TOPOLOGY 2020-02-05T07:01:11Z TSDELRVW
84/KQXA/VZVA GET_TOPOLOGY 2020-02-05T07:01:11Z TSDELRVW
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You say this is actually 6 rows. what are they?&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;I tried to use sort command on top of the query but it is not working&lt;/CODE&gt;&lt;BR /&gt;
ans: some value is multivalue. so, &lt;CODE&gt;sort&lt;/CODE&gt; is not work.&lt;BR /&gt;
&lt;CODE&gt;When I try to export it is not exporting as rows but it is exporting in to single row with entire data. How to export it as normal excel&lt;/CODE&gt;&lt;BR /&gt;
ans: If you want to export, you should use &lt;CODE&gt;table&lt;/CODE&gt; at last.       &lt;/P&gt;</description>
      <pubDate>Sat, 15 Feb 2020 00:15:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464988#M131021</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-02-15T00:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464989#M131022</link>
      <description>&lt;P&gt;Hi to4kawa,&lt;/P&gt;

&lt;P&gt;Let me put my requirement in simple way with help of below events and logs.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Example:
index=test1
source:abc.log
Event 1:
&amp;lt;emp_request&amp;gt;
&amp;lt;name&amp;gt;sam&amp;lt;/name&amp;gt;
&amp;lt;age&amp;gt;32&amp;lt;/age&amp;gt;
&amp;lt;eid&amp;gt;123&amp;lt;eid&amp;gt;
&amp;lt;/emp_request&amp;gt;

index=test2
source pqr.log
Event 1:
&amp;lt;emp_request&amp;gt;
&amp;lt;name&amp;gt;sam&amp;lt;/name&amp;gt;
&amp;lt;age&amp;gt;32&amp;lt;/age&amp;gt;
&amp;lt;eid&amp;gt;123&amp;lt;eid&amp;gt;
&amp;lt;/emp_request&amp;gt;

Event 2:
&amp;lt;emp_request&amp;gt;
&amp;lt;name&amp;gt;sam&amp;lt;/name&amp;gt;
&amp;lt;age&amp;gt;32&amp;lt;/age&amp;gt;
&amp;lt;eid&amp;gt;123&amp;lt;eid&amp;gt;
&amp;lt;tranid&amp;gt;456&amp;lt;/tranid&amp;gt; -- This log is adding this extra field into above xml and sends down
&amp;lt;/emp_request&amp;gt;

source:xyz.log
Event 1:

&amp;lt;emp_request&amp;gt;
&amp;lt;name&amp;gt;sam&amp;lt;/name&amp;gt;
&amp;lt;age&amp;gt;32&amp;lt;/age&amp;gt;
&amp;lt;eid&amp;gt;123&amp;lt;eid&amp;gt;
&amp;lt;tranid&amp;gt;456&amp;lt;/tranid&amp;gt; 
&amp;lt;/emp_request&amp;gt;


Event 2:
&amp;lt;emp_response&amp;gt;
&amp;lt;name&amp;gt;sam&amp;lt;/name&amp;gt;
&amp;lt;age&amp;gt;32&amp;lt;/age&amp;gt;
&amp;lt;eid&amp;gt;123&amp;lt;eid&amp;gt;
&amp;lt;tranid&amp;gt;456&amp;lt;/tranid&amp;gt; 
&amp;lt;sal&amp;gt;100$&amp;lt;/sal -- This is new field this log is adding in response to above req xml
&amp;lt;bonus&amp;gt;0.25&amp;lt;/bonus&amp;gt; -- This is new field this log is adding in response to above req xml
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The above response xml event in source:xyz.log will also be available in source abc.log &amp;amp; pqr.log because it is the final response send from xyz.log to pqr.log which in turn sends to abc.log&lt;/P&gt;

&lt;P&gt;Now I need below columns as single row table output if I search with my emp name sam&lt;BR /&gt;
name|eid|tranid|esal|bonus &lt;/P&gt;

&lt;P&gt;Note:I need esal &amp;amp; bonus to picked from Event 2 in source xyz.log and name &amp;amp; eid from Event 1 in source abc.log and tranid from Event 2 of source pqr.log&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 13:57:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464989#M131022</guid>
      <dc:creator>poddraj</dc:creator>
      <dc:date>2020-02-18T13:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to get single row output with fields from multiple events from multiple log files</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464990#M131023</link>
      <description>&lt;P&gt;you say &lt;CODE&gt;6 rows events&lt;/CODE&gt;&lt;BR /&gt;
In splunk, these are multivalues.not row.&lt;BR /&gt;
&lt;CODE&gt;single row&lt;/CODE&gt;, these are already single.&lt;BR /&gt;
how do you display these?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 20:36:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-get-single-row-output-with-fields-from-multiple-events/m-p/464990#M131023</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-02-18T20:36:48Z</dc:date>
    </item>
  </channel>
</rss>

