<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Iist IPs from different columns in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Iist-IPs-from-different-columns/m-p/361588#M165182</link>
    <description>&lt;P&gt;Thanks.  This is I am looking for.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Nov 2017 16:31:09 GMT</pubDate>
    <dc:creator>splunkrocks2014</dc:creator>
    <dc:date>2017-11-14T16:31:09Z</dc:date>
    <item>
      <title>Iist IPs from different columns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Iist-IPs-from-different-columns/m-p/361586#M165180</link>
      <description>&lt;P&gt;Is it an easy way to list IP's from different columns into one?  For instance,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;header     ip1         ip2       ip3
-------   -------    --------   --------
record1   1.1.1.1    2.2.2.2    3.3.3.3
record2    4.4.4.4   5.5.5.5    6.6.6.6
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The end result looks like the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; header      ip
 ---------- -----------
 record1    1.1.1.1
            2.2.2.2
            3.3.3.3
 record2    4.4.4.4
            5.5.5.5
            6.6.6.6
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is my search query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval header="record1", ip1="1.1.1.1", ip2="2.2.2.2", ip3="3.3.3.3" 
| append [| makeresults | eval header="record2", ip1="4.4.4.4", ip2="5.5.5.5", ip3="6.6.6.6"] 
| fields - _time 
| eval ip=ip1+"|" + ip2+"|"+ip3 
| fields - ip1 ip2 ip3 
| makemv delim="|" ip
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It works as expected, but it seems cumbersome.  Is there a better way to achieve the same result?  Thanks.   &lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 15:29:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Iist-IPs-from-different-columns/m-p/361586#M165180</guid>
      <dc:creator>splunkrocks2014</dc:creator>
      <dc:date>2017-11-14T15:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Iist IPs from different columns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Iist-IPs-from-different-columns/m-p/361587#M165181</link>
      <description>&lt;P&gt;There are two easy ways.  &lt;/P&gt;

&lt;P&gt;First, if the event is a record that has been extracted and has a &lt;CODE&gt;_raw&lt;/CODE&gt; field...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval _raw="header=\"record1\", ip1=\"1.1.1.1\", ip2=\"2.2.2.2\", ip3=\"3.3.3.3\"" 
| append [| makeresults | eval _raw="header=\"record2\", ip1=\"4.4.4.4\", ip2=\"5.5.5.5\", ip3=\"6.6.6.6\""] 
| rex field=_raw "(?&amp;lt;myIP&amp;gt;\d+\.\d+\.\d+\.\d+)(\D|$)" max_match=0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Second, if the above is not the case...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval header="record1", ip1="1.1.1.1", ip2="2.2.2.2", ip3="3.3.3.3" 
| append [| makeresults | eval header="record2", ip1="4.4.4.4", ip2="5.5.5.5", ip3="6.6.6.6"] 
| fields - _time
| streamstats count as recno
| untable recno fieldname fieldvalue
| regex fieldvalue="^\d+\.\d+\.\d+\.\d+$"
| stats list(fieldvalue) as myIP by recno
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 14 Nov 2017 15:55:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Iist-IPs-from-different-columns/m-p/361587#M165181</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-11-14T15:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Iist IPs from different columns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Iist-IPs-from-different-columns/m-p/361588#M165182</link>
      <description>&lt;P&gt;Thanks.  This is I am looking for.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 16:31:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Iist-IPs-from-different-columns/m-p/361588#M165182</guid>
      <dc:creator>splunkrocks2014</dc:creator>
      <dc:date>2017-11-14T16:31:09Z</dc:date>
    </item>
  </channel>
</rss>

