<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can i get only one data on column table instead of having multiple due to params? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563221#M196234</link>
    <description>&lt;TABLE width="1197"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="259.328px" height="25px"&gt;operationName&lt;/TD&gt;&lt;TD width="710.906px" height="25px"&gt;urls&lt;/TD&gt;&lt;TD width="81.4062px" height="25px"&gt;avg_time&lt;/TD&gt;&lt;TD width="83.2344px" height="25px"&gt;max_time&lt;/TD&gt;&lt;TD width="61.125px" height="25px"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="259.328px" height="25px"&gt;MethodUsingGET&lt;/TD&gt;&lt;TD width="710.906px" height="25px"&gt;&lt;A href="https://www.google.com/api/v1/571114808/CAR.202" target="_blank"&gt;https://www.google.com/api/v1/571114808/CAR.202&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.google.com/api/v1/571114899" target="_blank"&gt;https://www.google.com/api/v1/571114899&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD width="81.4062px" height="25px"&gt;3255&lt;/TD&gt;&lt;TD width="83.2344px" height="25px"&gt;3255&lt;/TD&gt;&lt;TD width="61.125px" height="25px"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="259.328px" height="91px"&gt;&lt;A href="https://www.google.com/api/v1" target="_blank"&gt;UsingGET&lt;/A&gt;&lt;/TD&gt;&lt;TD width="710.906px" height="91px"&gt;&lt;A href="https://www.google.com/api/v1/571114808" target="_blank"&gt;https://www.googleA.com/api/v1/571114888/api/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.googleB.com/api/v1/571114877" target="_blank"&gt;https://www.googleB.com/api/v1/571114877&lt;/A&gt;&lt;A href="https://www.google.com/api/v1/571114808" target="_blank"&gt;/api/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD width="81.4062px" height="91px"&gt;1316.889&lt;/TD&gt;&lt;TD width="83.2344px" height="91px"&gt;5345&lt;/TD&gt;&lt;TD width="61.125px" height="91px"&gt;18&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;I would only want one url but it should count others as well. Is there a way?&lt;/P&gt;</description>
    <pubDate>Fri, 13 Aug 2021 17:00:29 GMT</pubDate>
    <dc:creator>DougiieDee</dc:creator>
    <dc:date>2021-08-13T17:00:29Z</dc:date>
    <item>
      <title>How can i get only one data on column table instead of having multiple due to params?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563221#M196234</link>
      <description>&lt;TABLE width="1197"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="259.328px" height="25px"&gt;operationName&lt;/TD&gt;&lt;TD width="710.906px" height="25px"&gt;urls&lt;/TD&gt;&lt;TD width="81.4062px" height="25px"&gt;avg_time&lt;/TD&gt;&lt;TD width="83.2344px" height="25px"&gt;max_time&lt;/TD&gt;&lt;TD width="61.125px" height="25px"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="259.328px" height="25px"&gt;MethodUsingGET&lt;/TD&gt;&lt;TD width="710.906px" height="25px"&gt;&lt;A href="https://www.google.com/api/v1/571114808/CAR.202" target="_blank"&gt;https://www.google.com/api/v1/571114808/CAR.202&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.google.com/api/v1/571114899" target="_blank"&gt;https://www.google.com/api/v1/571114899&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD width="81.4062px" height="25px"&gt;3255&lt;/TD&gt;&lt;TD width="83.2344px" height="25px"&gt;3255&lt;/TD&gt;&lt;TD width="61.125px" height="25px"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="259.328px" height="91px"&gt;&lt;A href="https://www.google.com/api/v1" target="_blank"&gt;UsingGET&lt;/A&gt;&lt;/TD&gt;&lt;TD width="710.906px" height="91px"&gt;&lt;A href="https://www.google.com/api/v1/571114808" target="_blank"&gt;https://www.googleA.com/api/v1/571114888/api/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.googleB.com/api/v1/571114877" target="_blank"&gt;https://www.googleB.com/api/v1/571114877&lt;/A&gt;&lt;A href="https://www.google.com/api/v1/571114808" target="_blank"&gt;/api/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD width="81.4062px" height="91px"&gt;1316.889&lt;/TD&gt;&lt;TD width="83.2344px" height="91px"&gt;5345&lt;/TD&gt;&lt;TD width="61.125px" height="91px"&gt;18&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;I would only want one url but it should count others as well. Is there a way?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 17:00:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563221#M196234</guid>
      <dc:creator>DougiieDee</dc:creator>
      <dc:date>2021-08-13T17:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: How can i get only one data on column table instead of having multiple due to params?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563222#M196235</link>
      <description>&lt;P&gt;What search did you use to get these results? What do your events look like?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 17:13:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563222#M196235</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-13T17:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: How can i get only one data on column table instead of having multiple due to params?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563223#M196236</link>
      <description>&lt;P&gt;index=*&lt;BR /&gt;| rex "(?i)\".*?\":(?P&amp;lt;operationId&amp;gt;\d+)(?=,)"&lt;BR /&gt;| rex "(?i)\".*?\":(?P&amp;lt;responseTime&amp;gt;\d+)(?=,)"&lt;BR /&gt;| rex "(?i)\".*?\":(?P&amp;lt;Url&amp;gt;\d+)(?=,)"&lt;BR /&gt;| stats values(Url) as urls, avg(responseTime) as avg_time, max(responseTime) as max_time, count by operationId&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The results are in pretty in splunk but when i download the csv file all the results are in like 1 line and doesnt have data like it showed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 17:36:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563223#M196236</guid>
      <dc:creator>DougiieDee</dc:creator>
      <dc:date>2021-08-13T17:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: How can i get only one data on column table instead of having multiple due to params?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563225#M196237</link>
      <description>&lt;P&gt;Try something this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats avg(responseTime) as avg_time, max(responseTime) as max_time, count by operationId, Url&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 13 Aug 2021 17:47:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563225#M196237</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-13T17:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: How can i get only one data on column table instead of having multiple due to params?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563234#M196238</link>
      <description>&lt;P&gt;the results are like this&lt;/P&gt;&lt;TABLE width="868"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="148"&gt;operationId&lt;/TD&gt;&lt;TD width="511"&gt;Url&lt;/TD&gt;&lt;TD width="81"&gt;avg_time&lt;/TD&gt;&lt;TD width="64"&gt;max_time&lt;/TD&gt;&lt;TD width="64"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;accountUsingGET&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://*/api/account/history/sourceaccount" target="_blank"&gt;https://*/api/account/history/sourceaccount&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;1675.33333&lt;/TD&gt;&lt;TD&gt;4914&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;accountUsingGET&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://*/api/account/history/sourceaccount" target="_blank"&gt;https://*/api/account/history/sourceaccount&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;1324.7&lt;/TD&gt;&lt;TD&gt;5345&lt;/TD&gt;&lt;TD&gt;10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;LineUsingPOST&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://*/api/lines/1012/activate" target="_blank"&gt;https://*/api/lines/1012/activate&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;1224&lt;/TD&gt;&lt;TD&gt;1224&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;LineUsingPOST&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://*/api/lines/1014/activate" target="_blank"&gt;https://*/api/lines/1014/activate&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;1015&lt;/TD&gt;&lt;TD&gt;1015&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;LineUsingPOST&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://*/api/lines/1017/activate" target="_blank"&gt;https://*/api/lines/1017/activate&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;1506&lt;/TD&gt;&lt;TD&gt;1015&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but i only want one data from&amp;nbsp;operationId and Url but it should count all and give avg response time as well, like this, is there a way?&lt;/P&gt;&lt;TABLE width="868"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="148"&gt;operationId&lt;/TD&gt;&lt;TD width="511"&gt;Url&lt;/TD&gt;&lt;TD width="81"&gt;avg_time&lt;/TD&gt;&lt;TD width="64"&gt;max_time&lt;/TD&gt;&lt;TD width="64"&gt;count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;accountUsingGET&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://*/api/account/history/sourceaccount" target="_blank"&gt;https://*/api/account/history/sourceaccount&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;1675.33333&lt;/TD&gt;&lt;TD&gt;4914&lt;/TD&gt;&lt;TD&gt;13&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;LineUsingPOST&lt;/TD&gt;&lt;TD&gt;&lt;A href="https://*/api/lines/1012/activate" target="_blank"&gt;https://*/api/lines/1012/activate&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;1224&lt;/TD&gt;&lt;TD&gt;1224&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 18:31:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563234#M196238</guid>
      <dc:creator>DougiieDee</dc:creator>
      <dc:date>2021-08-13T18:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: How can i get only one data on column table instead of having multiple due to params?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563254#M196243</link>
      <description>&lt;P&gt;I don't think so - if you do stats by operationId, Url you will only get one row for each unique combination of these fields, which is what you said you wanted.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 20:49:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-i-get-only-one-data-on-column-table-instead-of-having/m-p/563254#M196243</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-13T20:49:27Z</dc:date>
    </item>
  </channel>
</rss>

