<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to keep the same value of a field in each row until the value of the field changes? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-keep-the-same-value-of-a-field-in-each-row-until-the/m-p/140892#M38989</link>
    <description>&lt;P&gt;Hello somesoni2,&lt;/P&gt;

&lt;P&gt;Thank you for your help but it is more complicated because that can be happen that another field3 appear with the same field1 value, for example :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;9/25/14 2:05:57.000, PM field1=abc, field2=ghi2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:56.000, PM field1=abc, field2=def2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:55.000, PM field1=abc, field2=abc2, field3=xyz3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:48.000, PM field1=abc, field2=ghi2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:47.000, PM field1=abc, field2=def2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:46.000, PM field1=abc, field2=abc2, field3=pzo3&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;And with your search, I have this :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;9/25/14 2:05:57.000, PM field1=abc, field2=ghi2, &lt;STRONG&gt;field3=pzo3&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:56.000, PM field1=abc, field2=def2, &lt;STRONG&gt;field3=pzo3&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:55.000, PM field1=abc, field2=abc2, &lt;STRONG&gt;field3=pzo3&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:48.000, PM field1=abc, field2=ghi2, field3=pzo3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:47.000, PM field1=abc, field2=def2, field3=pzo3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:46.000, PM field1=abc, field2=abc2, field3=pzo3&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;And I would like to have this :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;9/25/14 2:05:57.000, PM field1=abc, field2=ghi2, &lt;STRONG&gt;field3=xyz3&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:56.000, PM field1=abc, field2=def2, &lt;STRONG&gt;field3=xyz3&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:55.000, PM field1=abc, field2=abc2, &lt;STRONG&gt;field3=xyz3&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:48.000, PM field1=abc, field2=ghi2, field3=pzo3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:47.000, PM field1=abc, field2=def2, field3=pzo3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:46.000, PM field1=abc, field2=abc2, field3=pzo3&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Any idea ?&lt;/P&gt;

&lt;P&gt;Thanks for your help,&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 26 Sep 2014 09:16:28 GMT</pubDate>
    <dc:creator>ludoz13</dc:creator>
    <dc:date>2014-09-26T09:16:28Z</dc:date>
    <item>
      <title>How to keep the same value of a field in each row until the value of the field changes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-keep-the-same-value-of-a-field-in-each-row-until-the/m-p/140889#M38986</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I'd like to keep value on a field until the value of this field changes. Please see the following example:&lt;/P&gt;

&lt;P&gt;Explanation: I have:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;9/25/14 2:05:55.000, PM field1=abc, field2=abc2, field3=xyz3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:54.000, PM field1=abc, field2=def2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:53.000, PM field1=abc, field2=ghi2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:52.000, PM field1=jkl, field2=mno2, field3=vw3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:51.000, PM field1=jkl, field2=pqr2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:50.000, PM field1=jkl, field2=stu2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:49.000, PM field1=test, field2=tst2, field3=tre3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:48.000, PM field1=test, field2=psq2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:47.000, PM field1=test, field2=aaz2&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I would like to do&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;9/25/14 2:05:55.000, PM field1=abc, field2=abc2, field3=xyz3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:54.000, PM field1=abc, field2=def2, field3=xyz3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:53.000, PM field1=abc, field2=ghi2, field3=xyz3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:52.000, PM field1=jkl, field2=mno2, field3=vw3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:51.000, PM field1=jkl, field2=pqr2, field3=vw3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:50.000, PM field1=jkl, field2=stu2, field3=vw3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:49.000, PM field1=test, field2=tst2, field3=tre3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:48.000, PM field1=test, field2=psq2, field3=tre3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:47.000, PM field1=test, field2=aaz2, field3=tre3&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Would anyone have any idea?&lt;/P&gt;

&lt;P&gt;Thanks a lot for your help,&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;Ludovic&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2014 16:02:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-keep-the-same-value-of-a-field-in-each-row-until-the/m-p/140889#M38986</guid>
      <dc:creator>ludoz13</dc:creator>
      <dc:date>2014-09-25T16:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to keep the same value of a field in each row until the value of the field changes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-keep-the-same-value-of-a-field-in-each-row-until-the/m-p/140890#M38987</link>
      <description>&lt;P&gt;If possible, I'd recommend updating the original code or system to just record that info.  That said, it's not always possible, so you could go with something like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;base searchy... | streamstats current=f last(field3) AS newfield | eval field3=if(isnull(field3),newfield,field3) | table _time field1 field2 field3
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The streamstats command will carry forward the value; the eval basically checks to see if it already existed, and if so, retain the new value.  Bit of a roundabout way to do it, there might be a better way.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2014 17:36:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-keep-the-same-value-of-a-field-in-each-row-until-the/m-p/140890#M38987</guid>
      <dc:creator>srioux</dc:creator>
      <dc:date>2014-09-25T17:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to keep the same value of a field in each row until the value of the field changes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-keep-the-same-value-of-a-field-in-each-row-until-the/m-p/140891#M38988</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search with _time field1, field2, field3 | eventstats first(field3) as field3 by field1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 25 Sep 2014 21:36:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-keep-the-same-value-of-a-field-in-each-row-until-the/m-p/140891#M38988</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-09-25T21:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to keep the same value of a field in each row until the value of the field changes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-keep-the-same-value-of-a-field-in-each-row-until-the/m-p/140892#M38989</link>
      <description>&lt;P&gt;Hello somesoni2,&lt;/P&gt;

&lt;P&gt;Thank you for your help but it is more complicated because that can be happen that another field3 appear with the same field1 value, for example :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;9/25/14 2:05:57.000, PM field1=abc, field2=ghi2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:56.000, PM field1=abc, field2=def2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:55.000, PM field1=abc, field2=abc2, field3=xyz3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:48.000, PM field1=abc, field2=ghi2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:47.000, PM field1=abc, field2=def2&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:46.000, PM field1=abc, field2=abc2, field3=pzo3&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;And with your search, I have this :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;9/25/14 2:05:57.000, PM field1=abc, field2=ghi2, &lt;STRONG&gt;field3=pzo3&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:56.000, PM field1=abc, field2=def2, &lt;STRONG&gt;field3=pzo3&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:55.000, PM field1=abc, field2=abc2, &lt;STRONG&gt;field3=pzo3&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:48.000, PM field1=abc, field2=ghi2, field3=pzo3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:47.000, PM field1=abc, field2=def2, field3=pzo3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:46.000, PM field1=abc, field2=abc2, field3=pzo3&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;And I would like to have this :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;9/25/14 2:05:57.000, PM field1=abc, field2=ghi2, &lt;STRONG&gt;field3=xyz3&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:56.000, PM field1=abc, field2=def2, &lt;STRONG&gt;field3=xyz3&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:55.000, PM field1=abc, field2=abc2, &lt;STRONG&gt;field3=xyz3&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:48.000, PM field1=abc, field2=ghi2, field3=pzo3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:47.000, PM field1=abc, field2=def2, field3=pzo3&lt;/LI&gt;
&lt;LI&gt;9/25/14 2:05:46.000, PM field1=abc, field2=abc2, field3=pzo3&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Any idea ?&lt;/P&gt;

&lt;P&gt;Thanks for your help,&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2014 09:16:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-keep-the-same-value-of-a-field-in-each-row-until-the/m-p/140892#M38989</guid>
      <dc:creator>ludoz13</dc:creator>
      <dc:date>2014-09-26T09:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to keep the same value of a field in each row until the value of the field changes?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-keep-the-same-value-of-a-field-in-each-row-until-the/m-p/140893#M38990</link>
      <description>&lt;P&gt;Running into the same issue. Did you find any proper solution?&lt;/P&gt;

&lt;P&gt;Appreciate any help as this would make my life 1,000 times easier.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Tyler&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2015 23:06:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-keep-the-same-value-of-a-field-in-each-row-until-the/m-p/140893#M38990</guid>
      <dc:creator>tdiestel</dc:creator>
      <dc:date>2015-03-11T23:06:06Z</dc:date>
    </item>
  </channel>
</rss>

