<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Combining/appending multiple  makeresults in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Combining-appending-multiple-makeresults/m-p/554600#M157410</link>
    <description>&lt;P&gt;Since&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=hashstore

a.hash="aaaaaaaaa" OR a.hash="bbbbbbbbbb" OR a.hash="ccccccccccc"
OR
b.hash="aaaaaaaaa" OR b.hash="bbbbbbbbbb" OR b.hash="ccccccccccc"
OR
c.hash="aaaaaaaaa" OR c.hash="bbbbbbbbbb" OR c.hash="ccccccccccc"
OR
d.hash="aaaaaaaaa" OR d.hash="bbbbbbbbbb" OR d.hash="ccccccccccc"&lt;/LI-CODE&gt;&lt;P&gt;can be written as&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=hashstore

a.hash="aaaaaaaaa" OR 
a.hash="bbbbbbbbbb" OR 
a.hash="ccccccccccc" OR
b.hash="aaaaaaaaa" OR 
b.hash="bbbbbbbbbb" OR 
b.hash="ccccccccccc" OR
c.hash="aaaaaaaaa" OR 
c.hash="bbbbbbbbbb" OR 
c.hash="ccccccccccc" OR
d.hash="aaaaaaaaa" OR 
d.hash="bbbbbbbbbb" OR 
d.hash="ccccccccccc"&lt;/LI-CODE&gt;&lt;P&gt;your search can be something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=hashstore
    [| makeresults 
    | eval hash=split("abcd","")
    | mvexpand hash
    | eval hash=hash.".hash"
    | eval value=split("aaaaaaaaa,bbbbbbbbbb,ccccccccccc",",")
    | mvexpand value
    | eval {hash}=value
    | fields - _time hash value]&lt;/LI-CODE&gt;</description>
    <pubDate>Sun, 06 Jun 2021 08:09:08 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-06-06T08:09:08Z</dc:date>
    <item>
      <title>Combining/appending multiple  makeresults</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combining-appending-multiple-makeresults/m-p/554599#M157409</link>
      <description>&lt;P&gt;&lt;BR /&gt;I am providing data from one input in the dashboard, and want to search provided input strings in different fields which may include provided inputs. all the fields can contain same data format if they are not empty.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am using the following search, but not working.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; provided input can be single values as well.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Expected result:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=hashstore

a.hash="aaaaaaaaa" OR a.hash="bbbbbbbbbb" OR a.hash="ccccccccccc"
OR
b.hash="aaaaaaaaa" OR b.hash="bbbbbbbbbb" OR b.hash="ccccccccccc"
OR
c.hash="aaaaaaaaa" OR c.hash="bbbbbbbbbb" OR c.hash="ccccccccccc"
OR
d.hash="aaaaaaaaa" OR d.hash="bbbbbbbbbb" OR d.hash="ccccccccccc"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;CURRENT SEARCH&lt;/STRONG&gt;&lt;/U&gt; -- not giving the expected result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=hashstore


[| makeresults
| rename a.hash{} as hash
| eval a.hash="aaaaaaaaa,bbbbbbbbbb,ccccccccccc"
| eval a.hash=split(a.hash,",")
| mvexpand a.hash

| append
[| makeresults
| rename b.hash{} as b.hash
| eval b.hash="aaaaaaaaa,bbbbbbbbbb,ccccccccccc" | eval b.hash=split(b.hash,",")
| mvexpand b.hash
]
| append
[| makeresults
| rename c.hash{} as c.hash
| eval c.hash ="aaaaaaaaa,bbbbbbbbbb,ccccccccccc" | eval c.hash =split(c.hash ,",")
| mvexpand c.hash
]

| append
[| makeresults
| rename d.hash{} as d.hash
| eval d.hash="aaaaaaaaa,bbbbbbbbbb,ccccccccccc" | eval d.hash=split(d.hash,",")
| mvexpand d.hash
]


| table a.hash, b.hash, c.hash, d.hash
]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 07:47:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combining-appending-multiple-makeresults/m-p/554599#M157409</guid>
      <dc:creator>splunkerer</dc:creator>
      <dc:date>2021-06-06T07:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: Combining/appending multiple  makeresults</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combining-appending-multiple-makeresults/m-p/554600#M157410</link>
      <description>&lt;P&gt;Since&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=hashstore

a.hash="aaaaaaaaa" OR a.hash="bbbbbbbbbb" OR a.hash="ccccccccccc"
OR
b.hash="aaaaaaaaa" OR b.hash="bbbbbbbbbb" OR b.hash="ccccccccccc"
OR
c.hash="aaaaaaaaa" OR c.hash="bbbbbbbbbb" OR c.hash="ccccccccccc"
OR
d.hash="aaaaaaaaa" OR d.hash="bbbbbbbbbb" OR d.hash="ccccccccccc"&lt;/LI-CODE&gt;&lt;P&gt;can be written as&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=hashstore

a.hash="aaaaaaaaa" OR 
a.hash="bbbbbbbbbb" OR 
a.hash="ccccccccccc" OR
b.hash="aaaaaaaaa" OR 
b.hash="bbbbbbbbbb" OR 
b.hash="ccccccccccc" OR
c.hash="aaaaaaaaa" OR 
c.hash="bbbbbbbbbb" OR 
c.hash="ccccccccccc" OR
d.hash="aaaaaaaaa" OR 
d.hash="bbbbbbbbbb" OR 
d.hash="ccccccccccc"&lt;/LI-CODE&gt;&lt;P&gt;your search can be something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=hashstore
    [| makeresults 
    | eval hash=split("abcd","")
    | mvexpand hash
    | eval hash=hash.".hash"
    | eval value=split("aaaaaaaaa,bbbbbbbbbb,ccccccccccc",",")
    | mvexpand value
    | eval {hash}=value
    | fields - _time hash value]&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 06 Jun 2021 08:09:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combining-appending-multiple-makeresults/m-p/554600#M157410</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-06T08:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: Combining/appending multiple  makeresults</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combining-appending-multiple-makeresults/m-p/554601#M157411</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for solution, this is working fine, but the issue is my original field names are ending with {}. I forget to mention it, original search should be like below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I get this result?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=hashstore

a.hash{}="aaaaaaaaa" OR 
a.hash{}="bbbbbbbbbb" OR 
a.hash{}="ccccccccccc" OR
b.hash{}="aaaaaaaaa" OR 
b.hash{}="bbbbbbbbbb" OR 
b.hash{}="ccccccccccc" OR
c.hash{}="aaaaaaaaa" OR 
c.hash{}="bbbbbbbbbb" OR 
c.hash{}="ccccccccccc" OR
d.hash{}="aaaaaaaaa" OR 
d.hash{}="bbbbbbbbbb" OR 
d.hash{}="ccccccccccc"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jun 2021 14:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combining-appending-multiple-makeresults/m-p/554601#M157411</guid>
      <dc:creator>splunkerer</dc:creator>
      <dc:date>2021-06-06T14:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Combining/appending multiple  makeresults</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combining-appending-multiple-makeresults/m-p/554602#M157412</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=hashstore
    [| makeresults 
    | eval hash=split("abcd","")
    | mvexpand hash
    | eval hash=hash.".hash"
    | eval value=split("aaaaaaaaa,bbbbbbbbbb,ccccccccccc",",")
    | mvexpand value
    | eval {hash}=value
    | fields - _time hash value
    | rename * as *{}]&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 06 Jun 2021 15:18:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combining-appending-multiple-makeresults/m-p/554602#M157412</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-06T15:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Combining/appending multiple  makeresults</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combining-appending-multiple-makeresults/m-p/554726#M157450</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; you are the best!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 16:30:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combining-appending-multiple-makeresults/m-p/554726#M157450</guid>
      <dc:creator>splunkerer</dc:creator>
      <dc:date>2021-06-07T16:30:24Z</dc:date>
    </item>
  </channel>
</rss>

