<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to display other fields on the same row when aggregating using stats max(field)? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-other-fields-on-the-same-row-when-aggregating/m-p/660404#M228062</link>
    <description>&lt;P&gt;Thank you for your help for this question&lt;BR /&gt;Can you also help this related question?&amp;nbsp; &amp;nbsp; Thank you so much&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660403#M227978" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660403#M227978&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Oct 2023 15:01:59 GMT</pubDate>
    <dc:creator>LearningGuy</dc:creator>
    <dc:date>2023-10-11T15:01:59Z</dc:date>
    <item>
      <title>How to display other fields on the same row when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-other-fields-on-the-same-row-when-aggregating/m-p/660298#M228058</link>
      <description>&lt;P&gt;How to display other fields on the same row when aggregating using stats max(field)?&lt;BR /&gt;Thank you for your help.&amp;nbsp;&lt;BR /&gt;For example:&lt;BR /&gt;I am trying to display the same row that has the highest TotalScore=240&lt;/P&gt;&lt;TABLE width="462"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Class&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Subject&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="78"&gt;&lt;STRONG&gt;TotalScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score1&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score2&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score3&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name2&lt;/TD&gt;&lt;TD width="64"&gt;English&lt;/TD&gt;&lt;TD width="78"&gt;240&lt;/TD&gt;&lt;TD width="64"&gt;80&lt;/TD&gt;&lt;TD width="64"&gt;90&lt;/TD&gt;&lt;TD width="64"&gt;70&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;My Splunk Search&lt;/STRONG&gt;&lt;BR /&gt;| index=scoreindex&amp;nbsp; &amp;nbsp;&lt;BR /&gt;| stats values(Name) as Name, values(Subject) as Subject,&amp;nbsp; max(TotalScore) as TotalScore, max(Score1) as Score1, max(Score2) as Score2, max(Score3) as Score3 by Class&lt;BR /&gt;| table Class Name, Subject, Total Score, Score1, Score2, Score3&lt;BR /&gt;&lt;BR /&gt;I think my search below is going to display the following.&lt;/P&gt;&lt;TABLE width="462"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Class&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Subject&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="78"&gt;&lt;STRONG&gt;TotalScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score1&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score2&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score3&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name1 Name2 Name3&lt;/TD&gt;&lt;TD width="64"&gt;Math English&lt;/TD&gt;&lt;TD width="78"&gt;240&lt;/TD&gt;&lt;TD width="64"&gt;85&lt;/TD&gt;&lt;TD width="64"&gt;95&lt;/TD&gt;&lt;TD width="64"&gt;80&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;This is the whole data in table format from scoreindex&lt;/P&gt;&lt;TABLE width="495"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Class&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="90"&gt;&lt;STRONG&gt;Subject&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="85"&gt;&lt;STRONG&gt;TotalScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score1&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score2&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score3&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name1&lt;/TD&gt;&lt;TD width="90"&gt;Math&lt;/TD&gt;&lt;TD width="85"&gt;170&lt;/TD&gt;&lt;TD width="64"&gt;60&lt;/TD&gt;&lt;TD width="64"&gt;40&lt;/TD&gt;&lt;TD width="64"&gt;70&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name1&lt;/TD&gt;&lt;TD width="90"&gt;English&lt;/TD&gt;&lt;TD width="85"&gt;195&lt;/TD&gt;&lt;TD width="64"&gt;85&lt;/TD&gt;&lt;TD width="64"&gt;60&lt;/TD&gt;&lt;TD width="64"&gt;50&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name2&lt;/TD&gt;&lt;TD width="90"&gt;Math&lt;/TD&gt;&lt;TD width="85"&gt;175&lt;/TD&gt;&lt;TD width="64"&gt;50&lt;/TD&gt;&lt;TD width="64"&gt;60&lt;/TD&gt;&lt;TD width="64"&gt;65&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name2&lt;/TD&gt;&lt;TD width="90"&gt;English&lt;/TD&gt;&lt;TD width="85"&gt;240&lt;/TD&gt;&lt;TD width="64"&gt;80&lt;/TD&gt;&lt;TD width="64"&gt;90&lt;/TD&gt;&lt;TD width="64"&gt;70&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name3&lt;/TD&gt;&lt;TD width="90"&gt;Math&lt;/TD&gt;&lt;TD width="85"&gt;170&lt;/TD&gt;&lt;TD width="64"&gt;40&lt;/TD&gt;&lt;TD width="64"&gt;60&lt;/TD&gt;&lt;TD width="64"&gt;70&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name3&lt;/TD&gt;&lt;TD width="90"&gt;English&lt;/TD&gt;&lt;TD width="85"&gt;230&lt;/TD&gt;&lt;TD width="64"&gt;55&lt;/TD&gt;&lt;TD width="64"&gt;95&lt;/TD&gt;&lt;TD width="64"&gt;80&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 10 Oct 2023 20:21:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-other-fields-on-the-same-row-when-aggregating/m-p/660298#M228058</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-10-10T20:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to display other fields on the same row when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-other-fields-on-the-same-row-when-aggregating/m-p/660304#M228059</link>
      <description>&lt;P&gt;I am understanding that for your results you want to see who (Names) has the highest TotalScore for all classes.&lt;BR /&gt;&lt;BR /&gt;If my understanding is correct, here is one way you could structure that SPL.&amp;nbsp; I used&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Makeresults" target="_self"&gt;&lt;EM&gt;makeresults&lt;/EM&gt;&lt;/A&gt; to recreate your example table of data (thanks - that table helped me see what you're looking at):&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults format=csv data="Class,Name,Subject,TotalScore,Score1,Score2,Score3
ClassA,Name1,	Math,	170,	60	,40	,70
ClassA,Name1,	English	,195,	85,	60,	50
ClassA,Name2,	Math,	175,	50,	60,	65
ClassA,Name2,	English	,240,	80,	90,	70
ClassA,Name3,	Math,	170,	40,	60	,70
ClassA,Name3,	English	,230,	55,	95,	80"
| eventstats max(TotalScore) as max_TotalScore by Class, Subject
| where TotalScore=max_TotalScore
| table Class Name, Subject, TotalScore, Score1, Score2, Score3&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used the&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/eventstats" target="_self"&gt;&lt;EM&gt;eventstats&lt;/EM&gt; &lt;/A&gt;command to determine the highest scores by Class and Subject.&amp;nbsp; Essentially this will add a new field on each row called max_TotalScore.&amp;nbsp; I then use&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/where" target="_self"&gt;&lt;EM&gt;where&amp;nbsp;&lt;/EM&gt;&lt;/A&gt;to only keep the rows (i.e. Names) for the ones where the TotalScore equals this max_TotalScore - that means this person is the one with the highest score.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Results:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="class_max_TotalScore.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27519iDB695427835D1241/image-size/large?v=v2&amp;amp;px=999" role="button" title="class_max_TotalScore.png" alt="class_max_TotalScore.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 21:07:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-other-fields-on-the-same-row-when-aggregating/m-p/660304#M228059</guid>
      <dc:creator>_JP</dc:creator>
      <dc:date>2023-10-10T21:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to display other fields on the same row when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-other-fields-on-the-same-row-when-aggregating/m-p/660317#M228060</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I only need 1 row displaying all fields that has the Max TotalScore of 240&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;TABLE width="462"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Class&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Subject&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="78"&gt;&lt;STRONG&gt;TotalScore&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score1&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score2&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="64"&gt;&lt;STRONG&gt;Score3&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ClassA&lt;/TD&gt;&lt;TD width="64"&gt;Name2&lt;/TD&gt;&lt;TD width="64"&gt;English&lt;/TD&gt;&lt;TD width="78"&gt;240&lt;/TD&gt;&lt;TD width="64"&gt;80&lt;/TD&gt;&lt;TD width="64"&gt;90&lt;/TD&gt;&lt;TD width="64"&gt;70&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 21:25:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-other-fields-on-the-same-row-when-aggregating/m-p/660317#M228060</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-10-10T21:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to display other fields on the same row when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-other-fields-on-the-same-row-when-aggregating/m-p/660321#M228061</link>
      <description>&lt;P&gt;In this case if you just care about the max TotalScore, you can just reverse-&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Sort" target="_self"&gt;&lt;EM&gt;sort&lt;/EM&gt; &lt;/A&gt;your data by TotalScore and use&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Head" target="_self"&gt;&lt;EM&gt;head&lt;/EM&gt;&lt;/A&gt; to grab to first (aka the max) one:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults format=csv data="Class,Name,Subject,TotalScore,Score1,Score2,Score3
ClassA,Name1,	Math,	170,	60	,40	,70
ClassA,Name1,	English	,195,	85,	60,	50
ClassA,Name2,	Math,	175,	50,	60,	65
ClassA,Name2,	English	,240,	80,	90,	70
ClassA,Name3,	Math,	170,	40,	60	,70
ClassA,Name3,	English	,230,	55,	95,	80"
| sort -TotalScore
| head 1
| table Class Name, Subject, TotalScore, Score1, Score2, Score3&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Here's a screenshot:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="_JP_1-1696974281322.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27530i5ECF218266C92F70/image-size/medium?v=v2&amp;amp;px=400" role="button" title="_JP_1-1696974281322.png" alt="_JP_1-1696974281322.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 21:46:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-other-fields-on-the-same-row-when-aggregating/m-p/660321#M228061</guid>
      <dc:creator>_JP</dc:creator>
      <dc:date>2023-10-10T21:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to display other fields on the same row when aggregating using stats max(field)?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-display-other-fields-on-the-same-row-when-aggregating/m-p/660404#M228062</link>
      <description>&lt;P&gt;Thank you for your help for this question&lt;BR /&gt;Can you also help this related question?&amp;nbsp; &amp;nbsp; Thank you so much&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660403#M227978" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/How-to-calculate-total-when-aggregating-using-stats-max-field/m-p/660403#M227978&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 15:01:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-display-other-fields-on-the-same-row-when-aggregating/m-p/660404#M228062</guid>
      <dc:creator>LearningGuy</dc:creator>
      <dc:date>2023-10-11T15:01:59Z</dc:date>
    </item>
  </channel>
</rss>

