<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Merge the field value and its count into one field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645591#M223523</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257114"&gt;@man03359&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you already extracted the fields, in this case you have to count the occurrences of each error message using sats, and then you can merge both the fields in one filed, something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| stats count BY error_message
| eval error_message=error_message.": ".count
| table error_message&lt;/LI-CODE&gt;&lt;P&gt;If yu&amp;nbsp; have to extract the error_message field, you can try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| rex "(?ms)Error\s*Message\s*\=\s*(?&amp;lt;error_message&amp;gt;.*)Register"
| stats count BY error_message
| eval error_message=error_message.": ".count
| table error_message&lt;/LI-CODE&gt;&lt;P&gt;you can test the regex at&amp;nbsp;&lt;A href="https://regex101.com/r/ir5QRy/1" target="_blank"&gt;https://regex101.com/r/ir5QRy/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jun 2023 17:20:55 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-06-02T17:20:55Z</dc:date>
    <item>
      <title>How to merge the field value and its count into one field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645574#M223516</link>
      <description>&lt;P&gt;I am relatively new to Splunk and I am trying to create a field that contains the field value&amp;nbsp; and its count into one merged field,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The pattern looks like this:&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN class=""&gt;31/05/2023&lt;/SPAN&gt; &lt;SPAN class=""&gt;22:40:29&lt;/SPAN&gt; (&lt;SPAN class=""&gt;01&lt;/SPAN&gt;) &amp;gt;&amp;gt; &lt;SPAN class=""&gt;Adyen Proxy::Proxy::RaiseValidResponse::Proxy&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;event&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;received&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt;&amp;gt; &lt;SPAN class=""&gt;Result&lt;/SPAN&gt; &lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;FAILURE&lt;/SPAN&gt;&lt;/SPAN&gt; ; &lt;SPAN class=""&gt;Source&lt;/SPAN&gt; &lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;PROCESSPAYMENTFAILURE&lt;/SPAN&gt; ; &lt;SPAN class=""&gt;Message&lt;/SPAN&gt; &lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Validation&lt;/SPAN&gt; &lt;SPAN class=""&gt;failed:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Total&lt;/SPAN&gt; &lt;SPAN class=""&gt;amount&lt;/SPAN&gt; &lt;SPAN class=""&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;lower&lt;/SPAN&gt; &lt;SPAN class=""&gt;than&lt;/SPAN&gt; &lt;SPAN class=""&gt;configured&lt;/SPAN&gt; &lt;SPAN class=""&gt;min&lt;/SPAN&gt; &lt;SPAN class=""&gt;amount.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;UL class=""&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;Error Message =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="Validation failed: Total amount is lower than configured min amount.  " href="https://tjxprod.splunkcloud.com/en-GB/app/stores/search?earliest=-7d%40h&amp;amp;latest=now&amp;amp;q=search%20index%3Didx-stores-pos%20sourcetype%3DGSTR%3AAdyen%3Alog%20Failure%20OR%20RaiseValidResponse%3A%3AProxy%20event%20received%0A%7C%20eval%20Store%3D%20substr(host%2C1%2C7)%0A%7C%20search%20Store%3D%22*%22%0A%7C%20eval%20Register%3D%20substr(host%2C8%2C2)%0A%7C%20rex%20field%3D_raw%20%22AdyenPaymentResponse%3A.%2B%5CsResult%5Cs%3A%5Cs(%3F%3CStatus%3E.%2B)%22%0A%7C%20rex%20field%3D_raw%20%22RaiseValidResponse%3A.%2B%5CsMessage%5Cs%3A%5Cs(%3F%3CError_Message%3E.%2B)%22%0A%7C%20stats%20%0A%20%20%20count(eval(Status%3D%22Success%22))%20AS%20Success_Count%20%0A%20%20%20count(eval(Status%3D%22Failure%22))%20AS%20Failure_Count%20%0A%20%20%20BY%20Store%0A%7C%20eval%20Total%3D%20Success_Count%20%2B%20Failure_Count&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;display.general.type=statistics&amp;amp;display.page.search.tab=events&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22duration%22%2C%22report_hour%22%2C%22StateMessage%22%2C%22delta(_time)%22%2C%22Network%22%2C%22Platform%22%2C%22X_ARR_CACHE_HIT%22%2C%22cs_method%22%2C%22Invoice%22%2C%22Amount%22%2C%22TimeZoneName%22%2C%22CardType%22%2C%22ResponseText%22%2C%22HostRespCode%22%2C%22CardEntryMode%22%2C%22indextime%22%2C%22meraki_app%22%2C%22src_port%22%2C%22bytes_in%22%2C%22bytes_out%22%2C%22cluster_count%22%2C%22action%22%2C%22duration_ID%22%2C%22Store%22%2C%22Register%22%2C%22VHQInstance%22%2C%22Status%22%2C%22Error_Message%22%5D&amp;amp;sid=1685717047.155671_F4397435-7B3F-4F0E-A3FB-DF9FF7CC2A2E#" target="_blank" rel="noopener"&gt;Validation failed: Total amount is lower than configured min amount.&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;Register =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="01" href="https://tjxprod.splunkcloud.com/en-GB/app/stores/search?earliest=-7d%40h&amp;amp;latest=now&amp;amp;q=search%20index%3Didx-stores-pos%20sourcetype%3DGSTR%3AAdyen%3Alog%20Failure%20OR%20RaiseValidResponse%3A%3AProxy%20event%20received%0A%7C%20eval%20Store%3D%20substr(host%2C1%2C7)%0A%7C%20search%20Store%3D%22*%22%0A%7C%20eval%20Register%3D%20substr(host%2C8%2C2)%0A%7C%20rex%20field%3D_raw%20%22AdyenPaymentResponse%3A.%2B%5CsResult%5Cs%3A%5Cs(%3F%3CStatus%3E.%2B)%22%0A%7C%20rex%20field%3D_raw%20%22RaiseValidResponse%3A.%2B%5CsMessage%5Cs%3A%5Cs(%3F%3CError_Message%3E.%2B)%22%0A%7C%20stats%20%0A%20%20%20count(eval(Status%3D%22Success%22))%20AS%20Success_Count%20%0A%20%20%20count(eval(Status%3D%22Failure%22))%20AS%20Failure_Count%20%0A%20%20%20BY%20Store%0A%7C%20eval%20Total%3D%20Success_Count%20%2B%20Failure_Count&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;display.general.type=statistics&amp;amp;display.page.search.tab=events&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22duration%22%2C%22report_hour%22%2C%22StateMessage%22%2C%22delta(_time)%22%2C%22Network%22%2C%22Platform%22%2C%22X_ARR_CACHE_HIT%22%2C%22cs_method%22%2C%22Invoice%22%2C%22Amount%22%2C%22TimeZoneName%22%2C%22CardType%22%2C%22ResponseText%22%2C%22HostRespCode%22%2C%22CardEntryMode%22%2C%22indextime%22%2C%22meraki_app%22%2C%22src_port%22%2C%22bytes_in%22%2C%22bytes_out%22%2C%22cluster_count%22%2C%22action%22%2C%22duration_ID%22%2C%22Store%22%2C%22Register%22%2C%22VHQInstance%22%2C%22Status%22%2C%22Error_Message%22%5D&amp;amp;sid=1685717047.155671_F4397435-7B3F-4F0E-A3FB-DF9FF7CC2A2E#" target="_blank" rel="noopener"&gt;01&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;Store =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="tkg0452" href="https://tjxprod.splunkcloud.com/en-GB/app/stores/search?earliest=-7d%40h&amp;amp;latest=now&amp;amp;q=search%20index%3Didx-stores-pos%20sourcetype%3DGSTR%3AAdyen%3Alog%20Failure%20OR%20RaiseValidResponse%3A%3AProxy%20event%20received%0A%7C%20eval%20Store%3D%20substr(host%2C1%2C7)%0A%7C%20search%20Store%3D%22*%22%0A%7C%20eval%20Register%3D%20substr(host%2C8%2C2)%0A%7C%20rex%20field%3D_raw%20%22AdyenPaymentResponse%3A.%2B%5CsResult%5Cs%3A%5Cs(%3F%3CStatus%3E.%2B)%22%0A%7C%20rex%20field%3D_raw%20%22RaiseValidResponse%3A.%2B%5CsMessage%5Cs%3A%5Cs(%3F%3CError_Message%3E.%2B)%22%0A%7C%20stats%20%0A%20%20%20count(eval(Status%3D%22Success%22))%20AS%20Success_Count%20%0A%20%20%20count(eval(Status%3D%22Failure%22))%20AS%20Failure_Count%20%0A%20%20%20BY%20Store%0A%7C%20eval%20Total%3D%20Success_Count%20%2B%20Failure_Count&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;display.general.type=statistics&amp;amp;display.page.search.tab=events&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22duration%22%2C%22report_hour%22%2C%22StateMessage%22%2C%22delta(_time)%22%2C%22Network%22%2C%22Platform%22%2C%22X_ARR_CACHE_HIT%22%2C%22cs_method%22%2C%22Invoice%22%2C%22Amount%22%2C%22TimeZoneName%22%2C%22CardType%22%2C%22ResponseText%22%2C%22HostRespCode%22%2C%22CardEntryMode%22%2C%22indextime%22%2C%22meraki_app%22%2C%22src_port%22%2C%22bytes_in%22%2C%22bytes_out%22%2C%22cluster_count%22%2C%22action%22%2C%22duration_ID%22%2C%22Store%22%2C%22Register%22%2C%22VHQInstance%22%2C%22Status%22%2C%22Error_Message%22%5D&amp;amp;sid=1685717047.155671_F4397435-7B3F-4F0E-A3FB-DF9FF7CC2A2E#" target="_blank" rel="noopener"&gt;tkg0452&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;host =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="tkg045201.store.tjxcorp.net" href="https://tjxprod.splunkcloud.com/en-GB/app/stores/search?earliest=-7d%40h&amp;amp;latest=now&amp;amp;q=search%20index%3Didx-stores-pos%20sourcetype%3DGSTR%3AAdyen%3Alog%20Failure%20OR%20RaiseValidResponse%3A%3AProxy%20event%20received%0A%7C%20eval%20Store%3D%20substr(host%2C1%2C7)%0A%7C%20search%20Store%3D%22*%22%0A%7C%20eval%20Register%3D%20substr(host%2C8%2C2)%0A%7C%20rex%20field%3D_raw%20%22AdyenPaymentResponse%3A.%2B%5CsResult%5Cs%3A%5Cs(%3F%3CStatus%3E.%2B)%22%0A%7C%20rex%20field%3D_raw%20%22RaiseValidResponse%3A.%2B%5CsMessage%5Cs%3A%5Cs(%3F%3CError_Message%3E.%2B)%22%0A%7C%20stats%20%0A%20%20%20count(eval(Status%3D%22Success%22))%20AS%20Success_Count%20%0A%20%20%20count(eval(Status%3D%22Failure%22))%20AS%20Failure_Count%20%0A%20%20%20BY%20Store%0A%7C%20eval%20Total%3D%20Success_Count%20%2B%20Failure_Count&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;display.general.type=statistics&amp;amp;display.page.search.tab=events&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22duration%22%2C%22report_hour%22%2C%22StateMessage%22%2C%22delta(_time)%22%2C%22Network%22%2C%22Platform%22%2C%22X_ARR_CACHE_HIT%22%2C%22cs_method%22%2C%22Invoice%22%2C%22Amount%22%2C%22TimeZoneName%22%2C%22CardType%22%2C%22ResponseText%22%2C%22HostRespCode%22%2C%22CardEntryMode%22%2C%22indextime%22%2C%22meraki_app%22%2C%22src_port%22%2C%22bytes_in%22%2C%22bytes_out%22%2C%22cluster_count%22%2C%22action%22%2C%22duration_ID%22%2C%22Store%22%2C%22Register%22%2C%22VHQInstance%22%2C%22Status%22%2C%22Error_Message%22%5D&amp;amp;sid=1685717047.155671_F4397435-7B3F-4F0E-A3FB-DF9FF7CC2A2E#" target="_blank" rel="noopener"&gt;tkg045201.store.tjxcorp.net&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;source =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="C:\ProgramData\GlobalSTORE\AdyenLog_5_31_2023.log" href="https://tjxprod.splunkcloud.com/en-GB/app/stores/search?earliest=-7d%40h&amp;amp;latest=now&amp;amp;q=search%20index%3Didx-stores-pos%20sourcetype%3DGSTR%3AAdyen%3Alog%20Failure%20OR%20RaiseValidResponse%3A%3AProxy%20event%20received%0A%7C%20eval%20Store%3D%20substr(host%2C1%2C7)%0A%7C%20search%20Store%3D%22*%22%0A%7C%20eval%20Register%3D%20substr(host%2C8%2C2)%0A%7C%20rex%20field%3D_raw%20%22AdyenPaymentResponse%3A.%2B%5CsResult%5Cs%3A%5Cs(%3F%3CStatus%3E.%2B)%22%0A%7C%20rex%20field%3D_raw%20%22RaiseValidResponse%3A.%2B%5CsMessage%5Cs%3A%5Cs(%3F%3CError_Message%3E.%2B)%22%0A%7C%20stats%20%0A%20%20%20count(eval(Status%3D%22Success%22))%20AS%20Success_Count%20%0A%20%20%20count(eval(Status%3D%22Failure%22))%20AS%20Failure_Count%20%0A%20%20%20BY%20Store%0A%7C%20eval%20Total%3D%20Success_Count%20%2B%20Failure_Count&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;display.general.type=statistics&amp;amp;display.page.search.tab=events&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22duration%22%2C%22report_hour%22%2C%22StateMessage%22%2C%22delta(_time)%22%2C%22Network%22%2C%22Platform%22%2C%22X_ARR_CACHE_HIT%22%2C%22cs_method%22%2C%22Invoice%22%2C%22Amount%22%2C%22TimeZoneName%22%2C%22CardType%22%2C%22ResponseText%22%2C%22HostRespCode%22%2C%22CardEntryMode%22%2C%22indextime%22%2C%22meraki_app%22%2C%22src_port%22%2C%22bytes_in%22%2C%22bytes_out%22%2C%22cluster_count%22%2C%22action%22%2C%22duration_ID%22%2C%22Store%22%2C%22Register%22%2C%22VHQInstance%22%2C%22Status%22%2C%22Error_Message%22%5D&amp;amp;sid=1685717047.155671_F4397435-7B3F-4F0E-A3FB-DF9FF7CC2A2E#" target="_blank" rel="noopener"&gt;C:\ProgramData\GlobalSTORE\AdyenLog_5_31_2023.log&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class=""&gt;sourcetype =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" title="GSTR:Adyen:log" href="https://tjxprod.splunkcloud.com/en-GB/app/stores/search?earliest=-7d%40h&amp;amp;latest=now&amp;amp;q=search%20index%3Didx-stores-pos%20sourcetype%3DGSTR%3AAdyen%3Alog%20Failure%20OR%20RaiseValidResponse%3A%3AProxy%20event%20received%0A%7C%20eval%20Store%3D%20substr(host%2C1%2C7)%0A%7C%20search%20Store%3D%22*%22%0A%7C%20eval%20Register%3D%20substr(host%2C8%2C2)%0A%7C%20rex%20field%3D_raw%20%22AdyenPaymentResponse%3A.%2B%5CsResult%5Cs%3A%5Cs(%3F%3CStatus%3E.%2B)%22%0A%7C%20rex%20field%3D_raw%20%22RaiseValidResponse%3A.%2B%5CsMessage%5Cs%3A%5Cs(%3F%3CError_Message%3E.%2B)%22%0A%7C%20stats%20%0A%20%20%20count(eval(Status%3D%22Success%22))%20AS%20Success_Count%20%0A%20%20%20count(eval(Status%3D%22Failure%22))%20AS%20Failure_Count%20%0A%20%20%20BY%20Store%0A%7C%20eval%20Total%3D%20Success_Count%20%2B%20Failure_Count&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;display.general.type=statistics&amp;amp;display.page.search.tab=events&amp;amp;display.events.fields=%5B%22host%22%2C%22source%22%2C%22sourcetype%22%2C%22duration%22%2C%22report_hour%22%2C%22StateMessage%22%2C%22delta(_time)%22%2C%22Network%22%2C%22Platform%22%2C%22X_ARR_CACHE_HIT%22%2C%22cs_method%22%2C%22Invoice%22%2C%22Amount%22%2C%22TimeZoneName%22%2C%22CardType%22%2C%22ResponseText%22%2C%22HostRespCode%22%2C%22CardEntryMode%22%2C%22indextime%22%2C%22meraki_app%22%2C%22src_port%22%2C%22bytes_in%22%2C%22bytes_out%22%2C%22cluster_count%22%2C%22action%22%2C%22duration_ID%22%2C%22Store%22%2C%22Register%22%2C%22VHQInstance%22%2C%22Status%22%2C%22Error_Message%22%5D&amp;amp;sid=1685717047.155671_F4397435-7B3F-4F0E-A3FB-DF9FF7CC2A2E#" target="_blank" rel="noopener"&gt;GSTR:Adyen:log&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P&gt;I am trying to create one field&amp;nbsp; (e.g. Error and its count )&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First need to do the count of current field "Error_Message" and then merge the count with the field value&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 14:20:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645574#M223516</guid>
      <dc:creator>man03359</dc:creator>
      <dc:date>2023-06-05T14:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Merge the field value and its count into one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645591#M223523</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/257114"&gt;@man03359&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you already extracted the fields, in this case you have to count the occurrences of each error message using sats, and then you can merge both the fields in one filed, something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| stats count BY error_message
| eval error_message=error_message.": ".count
| table error_message&lt;/LI-CODE&gt;&lt;P&gt;If yu&amp;nbsp; have to extract the error_message field, you can try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt;
| rex "(?ms)Error\s*Message\s*\=\s*(?&amp;lt;error_message&amp;gt;.*)Register"
| stats count BY error_message
| eval error_message=error_message.": ".count
| table error_message&lt;/LI-CODE&gt;&lt;P&gt;you can test the regex at&amp;nbsp;&lt;A href="https://regex101.com/r/ir5QRy/1" target="_blank"&gt;https://regex101.com/r/ir5QRy/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 17:20:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645591#M223523</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-06-02T17:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: Merge the field value and its count into one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645774#M223586</link>
      <description>&lt;P&gt;Yes, I have extracted the field "Error_Message" using regex, current query is :&lt;/P&gt;&lt;P&gt;index=idx-stores-pos sourcetype=GSTR:Adyen:log&lt;BR /&gt;| eval Store= substr(host,1,7)&lt;BR /&gt;| eval Register= substr(host,8,2)&lt;BR /&gt;| rex field=_raw "AdyenPaymentResponse:.+\sResult\s:\s(?&amp;lt;Status&amp;gt;.+)"&lt;BR /&gt;| rex field=_raw "RaiseValidResponse:.+\sMessage\s:\s(?&amp;lt;Error_Message&amp;gt;.+)"&lt;BR /&gt;| stats&lt;BR /&gt;count(eval(Status="Success")) AS Success_Count&lt;BR /&gt;count(eval(Status="Failure")) AS Failure_Count&lt;BR /&gt;BY Store Register&lt;BR /&gt;| eval Total= Success_Count + Failure_Count&lt;/P&gt;&lt;P&gt;I am trying to get the value of field "Error_Message" and its count in separate column like this -&lt;/P&gt;&lt;TABLE width="673"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64"&gt;Store&amp;nbsp;&lt;/TD&gt;&lt;TD width="101"&gt;Register&lt;/TD&gt;&lt;TD width="110"&gt;Success_Count&lt;/TD&gt;&lt;TD width="101"&gt;Failure_Count&lt;/TD&gt;&lt;TD width="99"&gt;Total&lt;/TD&gt;&lt;TD width="99"&gt;Error_Message&lt;/TD&gt;&lt;TD width="99"&gt;Error_Count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 05 Jun 2023 13:19:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645774#M223586</guid>
      <dc:creator>man03359</dc:creator>
      <dc:date>2023-06-05T13:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Merge the field value and its count into one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645777#M223588</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;You must add all fields into stats line, which you want to use later on. In your case probably you should add it into by like "by Store Register Error_Message" another way could be ass it as "values(Error_Message) as Error_Message" before by clause.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 14:06:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645777#M223588</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-05T14:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: Merge the field value and its count into one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645793#M223595</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have tried Store Register Error_Message&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=idx-stores-pos sourcetype=GSTR:Adyen:log&amp;nbsp;&lt;BR /&gt;| eval Store= substr(host,1,7)&lt;BR /&gt;| search Store="*"&lt;BR /&gt;| eval Register= substr(host,8,2)&lt;BR /&gt;| rex field=_raw "AdyenPaymentResponse:.+\sResult\s:\s(?&amp;lt;Status&amp;gt;.+)"&lt;BR /&gt;| rex field=_raw "RaiseValidResponse:.+\sMessage\s:\s(?&amp;lt;Error_Message&amp;gt;.+)"&lt;BR /&gt;| stats&lt;BR /&gt;count(eval(Status="Success")) AS Success_Count&lt;BR /&gt;count(eval(Status="Failure")) AS Failure_Count&lt;BR /&gt;BY Store Register Error_Message&lt;BR /&gt;| eval Total= Success_Count + Failure_Count&lt;/P&gt;&lt;P&gt;it doesn't give the output for success_count, failure_count and total&lt;/P&gt;&lt;P&gt;Getting output like this --&lt;/P&gt;&lt;TABLE width="675"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="77"&gt;Store&lt;/TD&gt;&lt;TD width="93"&gt;Register&lt;/TD&gt;&lt;TD width="244"&gt;Error_Message&lt;/TD&gt;&lt;TD width="95"&gt;Success_Count&lt;/TD&gt;&lt;TD width="93"&gt;Failure_Count&lt;/TD&gt;&lt;TD width="73"&gt;Total&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;tkg0452&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;108 Shopper cancelled tx&amp;nbsp;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;tkg0452&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;PIN_TRIES_EXCEEDED&amp;nbsp;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;tkg0452&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;Validation failed: Total amount is lower than configured min amount.&amp;nbsp;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;tkg0452&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;WITHDRAWAL_AMOUNT_EXCEEDED&amp;nbsp;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;tkg0452&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;108 Shopper cancelled tx&amp;nbsp;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;tkg0452&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;219 Shopper cancelled ctls fallback&amp;nbsp;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 05 Jun 2023 17:08:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645793#M223595</guid>
      <dc:creator>man03359</dc:creator>
      <dc:date>2023-06-05T17:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Merge the field value and its count into one field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645859#M223610</link>
      <description>&lt;P&gt;It seems that your log sample is not matching to your Status field extraction. Can you add some sample logs inside &amp;lt;/&amp;gt; - editor block? Also Store and Register part is somehow unclear as you are pointing to host field which we don't know.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2023 07:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-the-field-value-and-its-count-into-one-field/m-p/645859#M223610</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-06-06T07:03:07Z</dc:date>
    </item>
  </channel>
</rss>

