<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Combine Status Results into one Row in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Combine-Status-Results-into-one-Row/m-p/340903#M160784</link>
    <description>&lt;P&gt;source="Test" index=XYZ [search source="Test2" index=XYZ2 Address=&lt;EM&gt;.&lt;/EM&gt;| dedup "attachments{}.uniqueid"|rename "attachments{}.uniqueid" as uniqueid|table uniqueid] |dedup uniqueid status|stats count(status) as Documents by status| eval status = case(status=42, "Entered Network", status=200, "Success Email Sent", status=333, "Processing Started", status=400 OR status=500, "Automatic Extraction", status=600 OR status=800, "Entered Validation", status=3, "Others")|eval sort_field=case(status="Entered Network",1,status="Success Email Sent",2,status="Processing Started",3,status="Automatic Extraction",4,status="Entered Validation",5,status="Others",6) | sort by sort_field|table status, Documents&lt;/P&gt;

&lt;P&gt;Everything works except I would like to combine Automatic Extraction into one row:&lt;/P&gt;

&lt;P&gt;Status                  Invoices&lt;BR /&gt;
Entered Network         46&lt;BR /&gt;
Success Email Sent      46&lt;BR /&gt;
Processing Started      44&lt;BR /&gt;
Automatic Extraction        47&lt;BR /&gt;
Automatic Extraction        42&lt;BR /&gt;
Entered Validation      56&lt;BR /&gt;
Others                  44&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 14:24:48 GMT</pubDate>
    <dc:creator>kartiksha</dc:creator>
    <dc:date>2020-09-29T14:24:48Z</dc:date>
    <item>
      <title>Combine Status Results into one Row</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combine-Status-Results-into-one-Row/m-p/340903#M160784</link>
      <description>&lt;P&gt;source="Test" index=XYZ [search source="Test2" index=XYZ2 Address=&lt;EM&gt;.&lt;/EM&gt;| dedup "attachments{}.uniqueid"|rename "attachments{}.uniqueid" as uniqueid|table uniqueid] |dedup uniqueid status|stats count(status) as Documents by status| eval status = case(status=42, "Entered Network", status=200, "Success Email Sent", status=333, "Processing Started", status=400 OR status=500, "Automatic Extraction", status=600 OR status=800, "Entered Validation", status=3, "Others")|eval sort_field=case(status="Entered Network",1,status="Success Email Sent",2,status="Processing Started",3,status="Automatic Extraction",4,status="Entered Validation",5,status="Others",6) | sort by sort_field|table status, Documents&lt;/P&gt;

&lt;P&gt;Everything works except I would like to combine Automatic Extraction into one row:&lt;/P&gt;

&lt;P&gt;Status                  Invoices&lt;BR /&gt;
Entered Network         46&lt;BR /&gt;
Success Email Sent      46&lt;BR /&gt;
Processing Started      44&lt;BR /&gt;
Automatic Extraction        47&lt;BR /&gt;
Automatic Extraction        42&lt;BR /&gt;
Entered Validation      56&lt;BR /&gt;
Others                  44&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:24:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combine-Status-Results-into-one-Row/m-p/340903#M160784</guid>
      <dc:creator>kartiksha</dc:creator>
      <dc:date>2020-09-29T14:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: Combine Status Results into one Row</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combine-Status-Results-into-one-Row/m-p/340904#M160785</link>
      <description>&lt;P&gt;Like --&lt;BR /&gt;
Status Invoices&lt;BR /&gt;
Entered Network 46&lt;BR /&gt;
Success Email Sent 46&lt;BR /&gt;
Processing Started 44&lt;BR /&gt;
&lt;STRONG&gt;Automatic Extraction 89&lt;/STRONG&gt;&lt;BR /&gt;
Entered Validation 56&lt;BR /&gt;
Others 44&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 08:25:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combine-Status-Results-into-one-Row/m-p/340904#M160785</guid>
      <dc:creator>kartiksha</dc:creator>
      <dc:date>2017-06-09T08:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Combine Status Results into one Row</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combine-Status-Results-into-one-Row/m-p/340905#M160786</link>
      <description>&lt;P&gt;you can add a &lt;CODE&gt;|stats sum(Documents) as Invoices by status&lt;/CODE&gt; at the end. or you could move your &lt;CODE&gt;|eval status&lt;/CODE&gt; before your &lt;CODE&gt;stats&lt;/CODE&gt; command.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 12:23:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combine-Status-Results-into-one-Row/m-p/340905#M160786</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-06-09T12:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Combine Status Results into one Row</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combine-Status-Results-into-one-Row/m-p/340906#M160787</link>
      <description>&lt;P&gt;Thanks. That was simple... I feel like an idiot &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 12:40:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combine-Status-Results-into-one-Row/m-p/340906#M160787</guid>
      <dc:creator>kartiksha</dc:creator>
      <dc:date>2017-06-09T12:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: Combine Status Results into one Row</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combine-Status-Results-into-one-Row/m-p/340907#M160788</link>
      <description>&lt;P&gt;you have no idea how easy it is to overlook the simplest things &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 12:49:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combine-Status-Results-into-one-Row/m-p/340907#M160788</guid>
      <dc:creator>cmerriman</dc:creator>
      <dc:date>2017-06-09T12:49:01Z</dc:date>
    </item>
  </channel>
</rss>

