<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to merge using time range and some duplicated field values? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-using-time-range-and-some-duplicated-field-values/m-p/653409#M225802</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a table with the following fields from an email security system that are duplicated within a time range of 3s:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;STRONG&gt;_time&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;&lt;STRONG&gt;sender&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;STRONG&gt;receiver&amp;nbsp; &amp;nbsp; &lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;STRONG&gt;subject&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;STRONG&gt;attach&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;SPAN&gt;2023-08-07 14:07:46&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;sender1@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;A href="mailto:receiver1@domain.com" target="_blank" rel="noopener"&gt;receiver1@domain.com&lt;/A&gt;&lt;BR /&gt;receiver2@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;"email subject"&lt;/TD&gt;
&lt;TD width="20%"&gt;
&lt;P&gt;attach1.pdf&lt;/P&gt;
&lt;P&gt;attach2.pdf&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;SPAN&gt;2023-08-07 14:07:49&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;sender1@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;A href="mailto:receiver1@domain.com" target="_blank" rel="noopener"&gt;receiver1@domain.com&lt;/A&gt;&lt;BR /&gt;receiver2@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;SPAN&gt;2023-08-07 15:10:05&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;sender2@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;A href="mailto:receiver1@domain.com" target="_blank" rel="noopener"&gt;receiver3@domain.com&lt;/A&gt;&lt;BR /&gt;receiver4@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;SPAN&gt;2023-08-07 15:10:08&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;sender2@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;A href="mailto:receiver1@domain.com" target="_blank" rel="noopener"&gt;receiver3@domain.com&lt;/A&gt;&lt;BR /&gt;receiver4@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;"email2 subject"&lt;/TD&gt;
&lt;TD width="20%"&gt;
&lt;P&gt;attach3.rar&lt;/P&gt;
&lt;P&gt;attach4.rar&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="20%"&gt;&lt;SPAN&gt;2023-08-07 16:11:08&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;sender3@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;receiver5@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;I want to merge the duplicated fields together within the range of 3s without losing the subject and attach value, but I don't want to remove other blank values of the emails that are sent without a subject or attach. It should look like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;STRONG&gt;_time&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;&lt;STRONG&gt;sender&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;STRONG&gt;receiver&amp;nbsp; &amp;nbsp; &lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;STRONG&gt;subject&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;STRONG&gt;attach&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;SPAN&gt;2023-08-07 14:07:46&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;sender1@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;A href="mailto:receiver1@domain.com" target="_blank" rel="noopener"&gt;receiver1@domain.com&lt;/A&gt;&lt;BR /&gt;receiver2@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;"email subject"&lt;/TD&gt;
&lt;TD width="20%"&gt;
&lt;P&gt;attach1.pdf&lt;/P&gt;
&lt;P&gt;attach2.pdf&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;SPAN&gt;2023-08-07 15:10:08&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;sender2@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;A href="mailto:receiver1@domain.com" target="_blank" rel="noopener"&gt;receiver3@domain.com&lt;/A&gt;&lt;BR /&gt;receiver4@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;"email2 subject"&lt;/TD&gt;
&lt;TD width="20%"&gt;
&lt;P&gt;attach3.rar&lt;/P&gt;
&lt;P&gt;attach4.rar&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="20%"&gt;&lt;SPAN&gt;2023-08-07 16:11:08&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;sender3@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;receiver5@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 07 Aug 2023 19:26:43 GMT</pubDate>
    <dc:creator>evallja</dc:creator>
    <dc:date>2023-08-07T19:26:43Z</dc:date>
    <item>
      <title>How to merge using time range and some duplicated field values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-using-time-range-and-some-duplicated-field-values/m-p/653409#M225802</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a table with the following fields from an email security system that are duplicated within a time range of 3s:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;STRONG&gt;_time&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;&lt;STRONG&gt;sender&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;STRONG&gt;receiver&amp;nbsp; &amp;nbsp; &lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;STRONG&gt;subject&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;STRONG&gt;attach&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;SPAN&gt;2023-08-07 14:07:46&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;sender1@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;A href="mailto:receiver1@domain.com" target="_blank" rel="noopener"&gt;receiver1@domain.com&lt;/A&gt;&lt;BR /&gt;receiver2@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;"email subject"&lt;/TD&gt;
&lt;TD width="20%"&gt;
&lt;P&gt;attach1.pdf&lt;/P&gt;
&lt;P&gt;attach2.pdf&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;SPAN&gt;2023-08-07 14:07:49&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;sender1@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;A href="mailto:receiver1@domain.com" target="_blank" rel="noopener"&gt;receiver1@domain.com&lt;/A&gt;&lt;BR /&gt;receiver2@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;SPAN&gt;2023-08-07 15:10:05&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;sender2@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;A href="mailto:receiver1@domain.com" target="_blank" rel="noopener"&gt;receiver3@domain.com&lt;/A&gt;&lt;BR /&gt;receiver4@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;SPAN&gt;2023-08-07 15:10:08&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;sender2@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;A href="mailto:receiver1@domain.com" target="_blank" rel="noopener"&gt;receiver3@domain.com&lt;/A&gt;&lt;BR /&gt;receiver4@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;"email2 subject"&lt;/TD&gt;
&lt;TD width="20%"&gt;
&lt;P&gt;attach3.rar&lt;/P&gt;
&lt;P&gt;attach4.rar&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="20%"&gt;&lt;SPAN&gt;2023-08-07 16:11:08&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;sender3@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;receiver5@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;I want to merge the duplicated fields together within the range of 3s without losing the subject and attach value, but I don't want to remove other blank values of the emails that are sent without a subject or attach. It should look like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;STRONG&gt;_time&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;&lt;STRONG&gt;sender&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;STRONG&gt;receiver&amp;nbsp; &amp;nbsp; &lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;STRONG&gt;subject&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;STRONG&gt;attach&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;SPAN&gt;2023-08-07 14:07:46&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;sender1@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;A href="mailto:receiver1@domain.com" target="_blank" rel="noopener"&gt;receiver1@domain.com&lt;/A&gt;&lt;BR /&gt;receiver2@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;"email subject"&lt;/TD&gt;
&lt;TD width="20%"&gt;
&lt;P&gt;attach1.pdf&lt;/P&gt;
&lt;P&gt;attach2.pdf&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="21.806451612903224%"&gt;&lt;SPAN&gt;2023-08-07 15:10:08&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="18.193548387096776%"&gt;sender2@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&lt;A href="mailto:receiver1@domain.com" target="_blank" rel="noopener"&gt;receiver3@domain.com&lt;/A&gt;&lt;BR /&gt;receiver4@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;"email2 subject"&lt;/TD&gt;
&lt;TD width="20%"&gt;
&lt;P&gt;attach3.rar&lt;/P&gt;
&lt;P&gt;attach4.rar&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="20%"&gt;&lt;SPAN&gt;2023-08-07 16:11:08&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD width="20%"&gt;sender3@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;receiver5@domain.com&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD width="20%"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 19:26:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-using-time-range-and-some-duplicated-field-values/m-p/653409#M225802</guid>
      <dc:creator>evallja</dc:creator>
      <dc:date>2023-08-07T19:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: merge using time range and some duplicated field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-merge-using-time-range-and-some-duplicated-field-values/m-p/653416#M225806</link>
      <description>&lt;LI-CODE lang="markup"&gt;| streamstats window=2 range(_time) as gap global=f by sender receiver
| eval _time=if(gap &amp;lt;= 3, _time-gap, _time)
| stats values(subject) as subject values(attach) as attach values(receiver) as receiver by _time sender&lt;/LI-CODE&gt;&lt;P&gt;This assumes the events are in chronological order and will use the time from the earlier of the pair of events&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 13:58:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-merge-using-time-range-and-some-duplicated-field-values/m-p/653416#M225806</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-07T13:58:53Z</dc:date>
    </item>
  </channel>
</rss>

