<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to Combine column from multiple search results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-Combine-column-from-multiple-search-results/m-p/657763#M227177</link>
    <description>&lt;P&gt;Hello, I have the following search&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=wineventlog EventCode=4728 OR EventCode = 4731 OR EventCode=4729 OR EventCode=4732 OR EventCode=4756  OR EventCode=4756 NOT src_user=*$
| rename src_user as admin, name as action
| table admin, Group_Name, user_name&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This spits out output like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin	Group_Name	user_name
adminx  GroupA  	UserA
adminx 	GroupB  	UserA
adminx 	GroupC  	UserA
adminy 	GroupD  	UserB
adminy 	GroupE  	UserB
adminy 	GroupF  	UserC
adminy 	GroupF  	UserD&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to combine them into a single message that looks like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin	Group_Name	        user_name
adminx  GroupA,GroupB,GroupC  	UserA
adminy 	GroupD,GroupE    	UserB
adminy 	GroupF  	        UserC,UserD&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What would be the best way to achieve that?&lt;/P&gt;</description>
    <pubDate>Mon, 18 Sep 2023 22:03:36 GMT</pubDate>
    <dc:creator>Niro</dc:creator>
    <dc:date>2023-09-18T22:03:36Z</dc:date>
    <item>
      <title>How to Combine column from multiple search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Combine-column-from-multiple-search-results/m-p/657763#M227177</link>
      <description>&lt;P&gt;Hello, I have the following search&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=wineventlog EventCode=4728 OR EventCode = 4731 OR EventCode=4729 OR EventCode=4732 OR EventCode=4756  OR EventCode=4756 NOT src_user=*$
| rename src_user as admin, name as action
| table admin, Group_Name, user_name&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This spits out output like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin	Group_Name	user_name
adminx  GroupA  	UserA
adminx 	GroupB  	UserA
adminx 	GroupC  	UserA
adminy 	GroupD  	UserB
adminy 	GroupE  	UserB
adminy 	GroupF  	UserC
adminy 	GroupF  	UserD&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to combine them into a single message that looks like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin	Group_Name	        user_name
adminx  GroupA,GroupB,GroupC  	UserA
adminy 	GroupD,GroupE    	UserB
adminy 	GroupF  	        UserC,UserD&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What would be the best way to achieve that?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 22:03:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Combine-column-from-multiple-search-results/m-p/657763#M227177</guid>
      <dc:creator>Niro</dc:creator>
      <dc:date>2023-09-18T22:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Combine column from multiple search results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Combine-column-from-multiple-search-results/m-p/657787#M227187</link>
      <description>&lt;LI-CODE lang="markup"&gt;| stats values(Group_Name) as Group_Name by admin user_name
| eval Group_Name=mvjoin(Group_Name, ",")
| stats values(user_name) as user_name by admin Group_Name
| eval user_name=mvjoin(user_name,",")&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 16 Sep 2023 05:55:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Combine-column-from-multiple-search-results/m-p/657787#M227187</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-09-16T05:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Combine column from multiple search results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Combine-column-from-multiple-search-results/m-p/657840#M227221</link>
      <description>&lt;P&gt;That worked perfectly, thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 03:59:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Combine-column-from-multiple-search-results/m-p/657840#M227221</guid>
      <dc:creator>Niro</dc:creator>
      <dc:date>2023-09-18T03:59:04Z</dc:date>
    </item>
  </channel>
</rss>

