<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to list multiple fields results for multiple fields by hosts. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562081#M195477</link>
    <description>&lt;P&gt;&lt;SPAN class="t"&gt;Yes, here is an example.&amp;nbsp; Thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;timestamp=1628083691&lt;/SPAN&gt; &lt;SPAN class="t"&gt;volumeTableDescription.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;IND&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableDescription.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;NMG&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableProvider.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Amazon&lt;/SPAN&gt; &lt;SPAN class="t"&gt;S3&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableProvider.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Amazon&lt;/SPAN&gt; &lt;SPAN class="t"&gt;S3&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableProtocol.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;proto_CIFS&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableProtocol.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;proto_CIFS&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableStatus.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;available&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableStatus.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;available&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableAccessibleData.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;792058246622&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableAccessibleData.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;431253442376050&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableUnprotectedData.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;248054173696&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableUnprotectedData.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotStart.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2021/Aug/04/12.16.31UTC&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotStart.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2021/Aug/04/13.08.44UTC&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotEnd.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2021/Aug/04/12.54.49UTC&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotEnd.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2021/Aug/04/13.08.56UTC&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotDuration.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2298&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotDuration.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;12&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotVersion.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;318&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotVersion.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;653391&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsActive.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsActive.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsShared.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsShared.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsReadOnly.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsReadOnly.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsPinned.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsPinned.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsRemote.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsRemote.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableAvEnabled.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableAvEnabled.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableRemoteAccessEnabled.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableRemoteAccessEnabled.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableQuota.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t h"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableQuota.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumAVViolations.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumAVViolations.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumFileAlerts.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumFileAlerts.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumExports.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumExports.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumShares.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;5&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumShares.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;5&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumFtpdirs.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumFtpdirs.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Aug 2021 13:29:58 GMT</pubDate>
    <dc:creator>dfalone</dc:creator>
    <dc:date>2021-08-04T13:29:58Z</dc:date>
    <item>
      <title>How to list multiple fields results for multiple fields by hosts.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/561954#M195443</link>
      <description>&lt;P&gt;Hi, I'm pretty new to Splunk and I'm creating a dashboard for one of my environments.&amp;nbsp; One thing I can't figure out is how to populate a table with entries from multiple fields into a&amp;nbsp; table sorted by host.&amp;nbsp; So it should look like this.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;HOST&lt;/STRONG&gt;&lt;/U&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;&lt;U&gt;VOLUME NAMES&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;A&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ARC&lt;/P&gt;&lt;P&gt;B&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ARC, LIV, FOR&lt;/P&gt;&lt;P&gt;C&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; LIV, FOR, FUN&lt;/P&gt;&lt;P&gt;The host and all of the volume names come from different fields.&amp;nbsp; Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 20:34:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/561954#M195443</guid>
      <dc:creator>dfalone</dc:creator>
      <dc:date>2021-08-03T20:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to list multiple fields results for multiple fields by hosts.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/561964#M195444</link>
      <description>&lt;P&gt;Can you share some sample events to show what you are dealing with?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 20:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/561964#M195444</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-03T20:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to list multiple fields results for multiple fields by hosts.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/561967#M195445</link>
      <description>&lt;P&gt;I tried the below but I get lots of entries with "empty" vol names and not sure how to also list by Host.&lt;/P&gt;&lt;P&gt;index=nasuni sourcetype=Nasuni_* | eval vol_combine = "" | fillnull value="" | foreach volumeTableDescription* [eval vol_combine=vol_combine." ".'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;'] | makemv vol_combine | table vol_combine&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalone_0-1628024472151.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15415i918DF94E6D6F7C8A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dfalone_0-1628024472151.png" alt="dfalone_0-1628024472151.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 21:01:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/561967#M195445</guid>
      <dc:creator>dfalone</dc:creator>
      <dc:date>2021-08-03T21:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to list multiple fields results for multiple fields by hosts.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/561973#M195446</link>
      <description>&lt;P&gt;Can you share the raw events that you have?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 21:49:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/561973#M195446</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-03T21:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to list multiple fields results for multiple fields by hosts.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562081#M195477</link>
      <description>&lt;P&gt;&lt;SPAN class="t"&gt;Yes, here is an example.&amp;nbsp; Thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;timestamp=1628083691&lt;/SPAN&gt; &lt;SPAN class="t"&gt;volumeTableDescription.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;IND&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableDescription.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;NMG&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableProvider.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Amazon&lt;/SPAN&gt; &lt;SPAN class="t"&gt;S3&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableProvider.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Amazon&lt;/SPAN&gt; &lt;SPAN class="t"&gt;S3&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableProtocol.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;proto_CIFS&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableProtocol.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;proto_CIFS&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableStatus.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;available&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableStatus.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;available&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableAccessibleData.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;792058246622&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableAccessibleData.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;431253442376050&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableUnprotectedData.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;248054173696&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableUnprotectedData.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotStart.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2021/Aug/04/12.16.31UTC&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotStart.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2021/Aug/04/13.08.44UTC&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotEnd.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2021/Aug/04/12.54.49UTC&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotEnd.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2021/Aug/04/13.08.56UTC&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotDuration.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;2298&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotDuration.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;12&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotVersion.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;318&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableLastSnapshotVersion.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;653391&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsActive.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsActive.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsShared.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsShared.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsReadOnly.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsReadOnly.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsPinned.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsPinned.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsRemote.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableIsRemote.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableAvEnabled.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableAvEnabled.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableRemoteAccessEnabled.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableRemoteAccessEnabled.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableQuota.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t h"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableQuota.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumAVViolations.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumAVViolations.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumFileAlerts.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumFileAlerts.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumExports.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumExports.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumShares.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;5&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumShares.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;5&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumFtpdirs.0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class="t"&gt;volumeTableNumFtpdirs.1&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 13:29:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562081#M195477</guid>
      <dc:creator>dfalone</dc:creator>
      <dc:date>2021-08-04T13:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to list multiple fields results for multiple fields by hosts.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562082#M195478</link>
      <description>&lt;P&gt;Thanks. It looks like that event works with your processing in that you get a mv field with IND and NMG in. Do you have an example of an event that doesn't work, or is it just a case that you want to ignore events which don't work?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 13:40:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562082#M195478</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-04T13:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to list multiple fields results for multiple fields by hosts.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562088#M195482</link>
      <description>&lt;P&gt;Your question actually helped, I was using a * in my sourcetype.&amp;nbsp; I changed it to only look at Volume and now the spaces are gone.&amp;nbsp; It now looks like below.&amp;nbsp; How do I add a Host field and show volumes per host?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalone_0-1628086269756.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15427i3E1BB66F2F75FC58/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dfalone_0-1628086269756.png" alt="dfalone_0-1628086269756.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 14:11:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562088#M195482</guid>
      <dc:creator>dfalone</dc:creator>
      <dc:date>2021-08-04T14:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to list multiple fields results for multiple fields by hosts.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562089#M195483</link>
      <description>&lt;P&gt;host would normally be added by the forwarders/indexers so you should just be able to reference it&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| table host vol_combine&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 04 Aug 2021 14:28:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562089#M195483</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-04T14:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to list multiple fields results for multiple fields by hosts.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562098#M195485</link>
      <description>&lt;P&gt;That works but now I have multiple entries for the same host reporting the same volume.&amp;nbsp; How do I get it to only list each host once with the respective volumes?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dfalone_0-1628089230750.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15429iB709C55166C7A527/image-size/medium?v=v2&amp;amp;px=400" role="button" title="dfalone_0-1628089230750.png" alt="dfalone_0-1628089230750.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 15:00:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562098#M195485</guid>
      <dc:creator>dfalone</dc:creator>
      <dc:date>2021-08-04T15:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to list multiple fields results for multiple fields by hosts.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562099#M195486</link>
      <description>&lt;LI-CODE lang="markup"&gt;| stats values(vol_combine) as vol_combine by host&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 04 Aug 2021 15:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562099#M195486</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-04T15:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to list multiple fields results for multiple fields by hosts.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562121#M195491</link>
      <description>&lt;P&gt;Thank you very much!&amp;nbsp; This is exactly what I needed. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 18:22:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-list-multiple-fields-results-for-multiple-fields-by-hosts/m-p/562121#M195491</guid>
      <dc:creator>dfalone</dc:creator>
      <dc:date>2021-08-04T18:22:16Z</dc:date>
    </item>
  </channel>
</rss>

