<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Summary Index - Eval Issue - Need both combined &amp;amp; segregated data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Summary-Index-Eval-Issue-Need-both-combined-amp-segregated-data/m-p/506362#M141673</link>
    <description>&lt;P&gt;Okay, look at what happens when you do these commands&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="css"&gt;| makeresults
| eval myfield1=mvappend("a","b","c")
| eval myfield2=mvjoin(myfield1,"!!!!")
| eval myfield3=makemv(myfield2,"!!!!") 

     &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;and then this command&lt;/P&gt;&lt;LI-CODE lang="css"&gt;| mvexpand myfield3&lt;/LI-CODE&gt;</description>
    <pubDate>Fri, 26 Jun 2020 21:33:43 GMT</pubDate>
    <dc:creator>DalJeanis</dc:creator>
    <dc:date>2020-06-26T21:33:43Z</dc:date>
    <item>
      <title>Summary Index - Eval Issue - Need both combined &amp; segregated data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Summary-Index-Eval-Issue-Need-both-combined-amp-segregated-data/m-p/505656#M141365</link>
      <description>&lt;P class="lia-align-left"&gt;Hi Splunk Experts&lt;/P&gt;&lt;P class="lia-align-left"&gt;I've created a summary index where it contains 6 eval cases, for example:&lt;/P&gt;&lt;P class="lia-align-left"&gt;eval 1=case(match(something,"a",...."b","c"), eval 2 =case (d,e,f)....eval 6=case(x,y,z)&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;where a,b,c....x,y,z are the individual detailed functions &amp;amp; 1,2,3,,4,5,6 as overall functions. Now I have combined all eval functions into a single value using eval Total_Function = mvappend(1,2,3,4,5,6).&lt;/P&gt;&lt;P class="lia-align-left"&gt;But I want to list the table with both overall function &amp;amp; individual detailed function as well. But I am not sure how to get individual detail values in the table along with overall function.&lt;/P&gt;&lt;P class="lia-align-left"&gt;Expected table as below:&lt;/P&gt;&lt;P class="lia-align-left"&gt;Time Total_Function&amp;nbsp; &amp;nbsp; &amp;nbsp; Overallfunction Individual function&lt;/P&gt;&lt;P class="lia-align-left"&gt;XX&amp;nbsp; &amp;nbsp; &amp;nbsp;T otal_Function&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;a&lt;BR /&gt;YY&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Total_Function&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;b&lt;BR /&gt;ZZ&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; Total_Function&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;c&lt;BR /&gt;AA&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; Total_Function&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;x&lt;BR /&gt;BB&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; Total_Function&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;6&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;y&lt;BR /&gt;CC&amp;nbsp; &amp;nbsp; &amp;nbsp; Total_Function&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 6&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;z&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;Kindly help me please.&lt;BR /&gt;&lt;BR /&gt;(Please note, there are multiple individual functions in each eval case)&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 06:26:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Summary-Index-Eval-Issue-Need-both-combined-amp-segregated-data/m-p/505656#M141365</guid>
      <dc:creator>gopiven</dc:creator>
      <dc:date>2020-06-23T06:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index - Eval Issue - Need both combined &amp; segregated data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Summary-Index-Eval-Issue-Need-both-combined-amp-segregated-data/m-p/505808#M141428</link>
      <description>&lt;P&gt;A summary index can contain literally any number of columns.&amp;nbsp; Just output the record with one column for each item you want to report.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, if an event had values for functions a, c r and t, and the Overall function was 1, then it might look like&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="css"&gt;(time) total_function=23, overall=1, a=12, c=7, r=0, t=15&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or, if I misunderstood your meaning, maybe it might be&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="css"&gt;(time) total_function=23 overall="1;3" detail="a;c;r;t"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="css"&gt;(time) total_function=23 overall="1;3" detail="a=12;c=7;r=0;t=15"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The next record does not have to have all the same fields.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 18:44:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Summary-Index-Eval-Issue-Need-both-combined-amp-segregated-data/m-p/505808#M141428</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2020-06-23T18:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index - Eval Issue - Need both combined &amp; segregated data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Summary-Index-Eval-Issue-Need-both-combined-amp-segregated-data/m-p/505855#M141484</link>
      <description>&lt;P&gt;Thanks for the reply. I guess you misunderstood the Question.&lt;BR /&gt;I am looking to segregate the individual fields which are already appended through mvappend command.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;mvappend(1,2,3,4,5,6)&lt;BR /&gt;1,2,3,4,5,6 are the eval function cases with values a,b....x,y,z(these values are calculated based on match criteria)&lt;BR /&gt;&lt;BR /&gt;Hence want to table the data as mentioned in the initial question.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 01:19:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Summary-Index-Eval-Issue-Need-both-combined-amp-segregated-data/m-p/505855#M141484</guid>
      <dc:creator>gopiven</dc:creator>
      <dc:date>2020-06-24T01:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index - Eval Issue - Need both combined &amp; segregated data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Summary-Index-Eval-Issue-Need-both-combined-amp-segregated-data/m-p/506362#M141673</link>
      <description>&lt;P&gt;Okay, look at what happens when you do these commands&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="css"&gt;| makeresults
| eval myfield1=mvappend("a","b","c")
| eval myfield2=mvjoin(myfield1,"!!!!")
| eval myfield3=makemv(myfield2,"!!!!") 

     &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;and then this command&lt;/P&gt;&lt;LI-CODE lang="css"&gt;| mvexpand myfield3&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 26 Jun 2020 21:33:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Summary-Index-Eval-Issue-Need-both-combined-amp-segregated-data/m-p/506362#M141673</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2020-06-26T21:33:43Z</dc:date>
    </item>
  </channel>
</rss>

