<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: using 'values' in stats shows values merged in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/using-values-in-stats-shows-values-merged/m-p/669161#M229517</link>
    <description>&lt;P&gt;You are correct, mvexpand of a values() or list() field will duplicate the event. If you want to count by ErrorCode separately, include ErrorCode in your by clause of the stats command.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Nov 2023 09:11:04 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-11-20T09:11:04Z</dc:date>
    <item>
      <title>using 'values' in stats shows values merged</title>
      <link>https://community.splunk.com/t5/Splunk-Search/using-values-in-stats-shows-values-merged/m-p/669140#M229516</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was wondering if you can help me figure out how do I show the merged values in a field as 'unmerged' when use 'values' in stats command&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="beriwalnishant_0-1700457913149.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28165i6E7B1F87E077E09B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="beriwalnishant_0-1700457913149.png" alt="beriwalnishant_0-1700457913149.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(DETAILS_SVC_ERROR) and (FARE/PRCNG/AVL-MULT. RSNS) are different values .... coming as merged as an example, its merging all values in one when used "Values" OR "List" how to unmerge same&lt;BR /&gt;&lt;BR /&gt;If I use 'mvexpand' it then expands to single count even if the values are same&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Nishant&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 05:29:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/using-values-in-stats-shows-values-merged/m-p/669140#M229516</guid>
      <dc:creator>beriwalnishant</dc:creator>
      <dc:date>2023-11-20T05:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: using 'values' in stats shows values merged</title>
      <link>https://community.splunk.com/t5/Splunk-Search/using-values-in-stats-shows-values-merged/m-p/669161#M229517</link>
      <description>&lt;P&gt;You are correct, mvexpand of a values() or list() field will duplicate the event. If you want to count by ErrorCode separately, include ErrorCode in your by clause of the stats command.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 09:11:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/using-values-in-stats-shows-values-merged/m-p/669161#M229517</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-20T09:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: using 'values' in stats shows values merged</title>
      <link>https://community.splunk.com/t5/Splunk-Search/using-values-in-stats-shows-values-merged/m-p/669276#M229550</link>
      <description>&lt;P&gt;But then I dont get the individual Totals if I do that along with the message.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 03:51:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/using-values-in-stats-shows-values-merged/m-p/669276#M229550</guid>
      <dc:creator>beriwalnishant</dc:creator>
      <dc:date>2023-11-21T03:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: using 'values' in stats shows values merged</title>
      <link>https://community.splunk.com/t5/Splunk-Search/using-values-in-stats-shows-values-merged/m-p/669304#M229559</link>
      <description>&lt;P&gt;Perhaps it would be better for you to show what it is that you do want?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 09:17:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/using-values-in-stats-shows-values-merged/m-p/669304#M229559</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-21T09:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: using 'values' in stats shows values merged</title>
      <link>https://community.splunk.com/t5/Splunk-Search/using-values-in-stats-shows-values-merged/m-p/669329#M229569</link>
      <description>&lt;P&gt;Well, this is how it's supposed to work. list() or values() gives you a multivalued field with a list of values.&lt;/P&gt;&lt;P&gt;If you need something else, you need to do something else.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 13:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/using-values-in-stats-shows-values-merged/m-p/669329#M229569</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-21T13:50:29Z</dc:date>
    </item>
  </channel>
</rss>

