<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: group same values into one value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-group-same-values-into-one-value/m-p/625274#M217367</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not sure to have understood your need, you could dedup using one field or use stats:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=indexname sourcetype=sourename
| eval Actualstarttime=strftime(strptime(NEXT_START,"%Y/%m/%d %H:%M:%S"),"%H:%M")
| eval Job_start_by=strftime(strptime(LAST_START,"%Y/%m/%d %H:%M:%S"),"%H:%M")
| stats  
   values(JOB_NAME) AS JOB_NAME
   values(JOB_GROUP) AS JOB_GROUP
   values(REGION) AS REGION
   values(TIMEZONE) AS TIMEZONE
   values(STATUS) AS STATUS
   values(Currenttime) AS Currenttime
   values(STATUS_TIME) AS STATUS_TIME
   values(LAST_START) AS LAST_START
   values(LAST_END) AS LAST_END
   values(NEXT_START) AS NEXT_START
   values(DAYS_OF_WEEK) AS DAYS_OF_WEEK
   values(EXCLUDE_CALENDAR) AS EXCLUDE_CALENDAR
   values(RUNTIME) AS RUNTIME
   values(Actualstarttime) AS Actualstarttime
   values(Job_start_by) AS Job_start_by
   values(START_SLA) AS START_SLA
   values(AVG_RUN_TIME) AS AVG_RUN_TIME
   BY BOX_NAME&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 26 Dec 2022 16:09:23 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-12-26T16:09:23Z</dc:date>
    <item>
      <title>How to group same values into one value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-group-same-values-into-one-value/m-p/625260#M217366</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how to group results of a same filed value into one fileld value&lt;/P&gt;
&lt;P&gt;from below table i have a field box-name and in the multiple value of same&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how can i group same value into one value&amp;nbsp; as below table for same value in BOX_NAME field how can i keep as one value&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;i am using search to table the results&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=indexname sourcetype=sourename
| eval Actualstarttime=strftime(strptime(NEXT_START,"%Y/%m/%d %H:%M:%S"),"%H:%M")
| eval Job_start_by=strftime(strptime(LAST_START,"%Y/%m/%d %H:%M:%S"),"%H:%M")
| table BOX_NAME,JOB_NAME,JOB_GROUP,REGION,TIMEZONE,STATUS,Currenttime,STATUS_TIME,LAST_START,LAST_END,NEXT_START,DAYS_OF_WEEK,EXCLUDE_CALENDAR,RUNTIME,Actualstarttime,Job_start_by,START_SLA,AVG_RUN_TIME



&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BOX_NAME JOB_NAME JOB_GROUP REGION TIMEZONE STATUS&lt;/P&gt;
&lt;TABLE width="414px"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="86.6979px"&gt;PNB-JAWS-USCA-ORDER-TCA-INBOUND-DAILY&lt;/TD&gt;
&lt;TD width="86.6979px"&gt;PNC-JAWS-USCA-ORDER-TCA-INBOUND-60ZIP&lt;/TD&gt;
&lt;TD width="53.5833px"&gt;JAWS&lt;/TD&gt;
&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="63.7604px"&gt;Central&lt;/TD&gt;
&lt;TD width="82.4792px"&gt;SUCCESS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="86.6979px"&gt;PNB-JAWS-USCA-ORDER-TCA-INBOUND-DAILY&lt;/TD&gt;
&lt;TD width="86.6979px"&gt;PNC-JAWS-USCA-ORDER-TCA-INBOUND-040INF&lt;/TD&gt;
&lt;TD width="53.5833px"&gt;JAWS&lt;/TD&gt;
&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="63.7604px"&gt;Central&lt;/TD&gt;
&lt;TD width="82.4792px"&gt;SUCCESS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="86.6979px"&gt;PNB-JAWS-USCA-ORDER-TCA-INBOUND-DAILY&lt;/TD&gt;
&lt;TD width="86.6979px"&gt;PNC-JAWS-USCA-ORDER-TCA-INBOUND-080DEL&lt;/TD&gt;
&lt;TD width="53.5833px"&gt;JAWS&lt;/TD&gt;
&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="63.7604px"&gt;Central&lt;/TD&gt;
&lt;TD width="82.4792px"&gt;SUCCESS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="86.6979px"&gt;PNB-JAWS-USCA-ORDER-TCA-INBOUND-DAILY&lt;/TD&gt;
&lt;TD width="86.6979px"&gt;PNC-JAWS-USCA-ORDER-TCA-INBOUND-010ARC&lt;/TD&gt;
&lt;TD width="53.5833px"&gt;JAWS&lt;/TD&gt;
&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="63.7604px"&gt;Central&lt;/TD&gt;
&lt;TD width="82.4792px"&gt;SUCCESS&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="86.6979px"&gt;PNB-JAWS-USCA-ORDER-TCA-INBOUND-DAILY&lt;/TD&gt;
&lt;TD width="86.6979px"&gt;PNC-JAWS-USCA-ORDER-TCA-INBOUND-025FW&lt;/TD&gt;
&lt;TD width="53.5833px"&gt;JAWS&lt;/TD&gt;
&lt;TD width="40px"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="63.7604px"&gt;Central&lt;/TD&gt;
&lt;TD width="82.4792px"&gt;SUCCESS&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 04:06:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-group-same-values-into-one-value/m-p/625260#M217366</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2022-12-29T04:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: group same values into one value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-group-same-values-into-one-value/m-p/625274#M217367</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not sure to have understood your need, you could dedup using one field or use stats:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=indexname sourcetype=sourename
| eval Actualstarttime=strftime(strptime(NEXT_START,"%Y/%m/%d %H:%M:%S"),"%H:%M")
| eval Job_start_by=strftime(strptime(LAST_START,"%Y/%m/%d %H:%M:%S"),"%H:%M")
| stats  
   values(JOB_NAME) AS JOB_NAME
   values(JOB_GROUP) AS JOB_GROUP
   values(REGION) AS REGION
   values(TIMEZONE) AS TIMEZONE
   values(STATUS) AS STATUS
   values(Currenttime) AS Currenttime
   values(STATUS_TIME) AS STATUS_TIME
   values(LAST_START) AS LAST_START
   values(LAST_END) AS LAST_END
   values(NEXT_START) AS NEXT_START
   values(DAYS_OF_WEEK) AS DAYS_OF_WEEK
   values(EXCLUDE_CALENDAR) AS EXCLUDE_CALENDAR
   values(RUNTIME) AS RUNTIME
   values(Actualstarttime) AS Actualstarttime
   values(Job_start_by) AS Job_start_by
   values(START_SLA) AS START_SLA
   values(AVG_RUN_TIME) AS AVG_RUN_TIME
   BY BOX_NAME&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 26 Dec 2022 16:09:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-group-same-values-into-one-value/m-p/625274#M217367</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-26T16:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: group same values into one value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-group-same-values-into-one-value/m-p/625303#M217368</link>
      <description>&lt;P&gt;hi Thanks for the search&lt;/P&gt;&lt;P&gt;i am getting expected results&amp;nbsp;&lt;/P&gt;&lt;P&gt;but for somevalues are missing it was showing only Unique values for any field&lt;/P&gt;&lt;P&gt;for example for RUNTIME field it will show 10 values for 10 JOB_NAME field&amp;nbsp;&lt;/P&gt;&lt;P&gt;but not showing for all of them like below is the out put values but showing only few&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;0&lt;BR /&gt;2&lt;BR /&gt;0&lt;BR /&gt;2&lt;BR /&gt;33&lt;BR /&gt;33&lt;BR /&gt;33&lt;BR /&gt;33&lt;BR /&gt;33&lt;BR /&gt;33&lt;BR /&gt;34&lt;BR /&gt;34&lt;BR /&gt;34&lt;BR /&gt;33&lt;BR /&gt;34&lt;BR /&gt;35&lt;BR /&gt;34&lt;BR /&gt;32&lt;BR /&gt;34&lt;BR /&gt;34&lt;BR /&gt;35&lt;BR /&gt;34&lt;BR /&gt;33&lt;BR /&gt;34&lt;BR /&gt;33&lt;BR /&gt;33&lt;BR /&gt;34&lt;BR /&gt;33&lt;BR /&gt;34&lt;BR /&gt;33&lt;BR /&gt;34&lt;BR /&gt;33&lt;BR /&gt;33&lt;BR /&gt;34&lt;BR /&gt;184&lt;BR /&gt;34&lt;BR /&gt;33&lt;BR /&gt;184&lt;BR /&gt;34&lt;BR /&gt;34&lt;BR /&gt;64&lt;BR /&gt;814&lt;BR /&gt;94&lt;BR /&gt;5&lt;BR /&gt;33&lt;BR /&gt;33&lt;BR /&gt;33&lt;BR /&gt;34&lt;BR /&gt;34&lt;BR /&gt;34&lt;BR /&gt;1053&lt;BR /&gt;33&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 08:37:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-group-same-values-into-one-value/m-p/625303#M217368</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2022-12-27T08:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: group same values into one value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-group-same-values-into-one-value/m-p/625305#M217369</link>
      <description>&lt;P&gt;It's not entirely clear what you mean.&lt;/P&gt;&lt;P&gt;If you want to have a "multirow" cell in your output visualization - kind of "groupping" of the rest of the row data - you can't do that. At least not with any of the built-in visualizations.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 09:00:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-group-same-values-into-one-value/m-p/625305#M217369</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-12-27T09:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: group same values into one value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-group-same-values-into-one-value/m-p/625307#M217370</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you don't want unique values but the list of values, you have to replace the values option with the list option, as described at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/CommonStatsFunctions" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/CommonStatsFunctions&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 09:01:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-group-same-values-into-one-value/m-p/625307#M217370</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-27T09:01:01Z</dc:date>
    </item>
  </channel>
</rss>

