<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I combine mv fields into a new field? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27682#M5407</link>
    <description>&lt;P&gt;Updated with information from the comment thread.  The correct way to do this for an mv field these days... &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | eval Field3=mvappend(Field1,Field2) | eval Field3=mvdedup(Field2) |
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or just &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | eval Field3=mvdedup(mvappend(Field1,Field2))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;HR /&gt;

&lt;P&gt;What I suggest:&lt;/P&gt;

&lt;P&gt;.... | eval Field3=coalesce(Field1,Field2) | dedup Field3 | ...&lt;/P&gt;

&lt;P&gt;I'm wondering if the problem is still in place, I found this thread because I had this issue :).&lt;/P&gt;</description>
    <pubDate>Thu, 08 Sep 2016 13:32:12 GMT</pubDate>
    <dc:creator>janwilbert</dc:creator>
    <dc:date>2016-09-08T13:32:12Z</dc:date>
    <item>
      <title>How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27675#M5400</link>
      <description>&lt;P&gt;I have events that have two multivalue fields, field1 and field2.  They look like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Field1          Field2
12345           12345
23456           34567
45678           45678
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How do I combine those fields to get all of the unique values from both of them into a single multivalue field?  The result I want is:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Field3
12345
23455
34567
45678
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks.&lt;/P&gt;

&lt;P&gt;Craig&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2011 16:04:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27675#M5400</guid>
      <dc:creator>jambajuice</dc:creator>
      <dc:date>2011-01-17T16:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27676#M5401</link>
      <description>&lt;P&gt;It's a little bit crude, but you can use some multivalue tricks to merge them like this: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;your search&amp;gt; 
| eval field1AsStr=mvjoin(field1,",") 
| eval field2AsStr=mvjoin(field2,",") 
| eval combined = field1AsStr + "," + field2AsStr 
| makemv delim="," combined 
| stats values(combined) as combined
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;To walk through it,   you join each of your fields into big unwieldy csv strings. Glue the strings together with a comma in the middle, and then split them on comma.     At this point you'll have duplicates so you need another stats values(combined) as combined to dedup the multivalue values.  &lt;/P&gt;

&lt;P&gt;hope that makes sense.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2011 16:36:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27676#M5401</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2011-01-18T16:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27677#M5402</link>
      <description>&lt;P&gt;I tried this and the problem is that sometimes Field1 is null and sometimes Field2 is null.  If either field is null, the eval option to combine the two strings ends up null.  How do I deal with null values?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2011 06:39:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27677#M5402</guid>
      <dc:creator>jambajuice</dc:creator>
      <dc:date>2011-01-21T06:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27678#M5403</link>
      <description>&lt;P&gt;sneak in a fillnull command beforehand and it should do the trick I think    | fillnull value="" Field1, Field2&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2011 07:16:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27678#M5403</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2011-01-21T07:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27679#M5404</link>
      <description>&lt;P&gt;Nick,&lt;BR /&gt;
This answer saved me today. It was exactly what I needed.  I made a macro out of it, so now I can call &lt;CODE&gt;make_mv_from_two_fields(field1,field2,finalfield)&lt;/CODE&gt;. I also created a macro to combine three as well.&lt;BR /&gt;
Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2012 04:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27679#M5404</guid>
      <dc:creator>sdwilkerson</dc:creator>
      <dc:date>2012-06-22T04:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27680#M5405</link>
      <description>&lt;P&gt;hi possible to share your macro for this ? &lt;BR /&gt;
Thanks. &lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2012 03:56:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27680#M5405</guid>
      <dc:creator>EricksonOng</dc:creator>
      <dc:date>2012-12-19T03:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27681#M5406</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;| eval mvappend(Field1,Field2)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Reference: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/SearchReference/CommonEvalFunctions#Multivalue_functions"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/SearchReference/CommonEvalFunctions#Multivalue_functions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 13:38:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27681#M5406</guid>
      <dc:creator>baldwintm</dc:creator>
      <dc:date>2015-12-03T13:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27682#M5407</link>
      <description>&lt;P&gt;Updated with information from the comment thread.  The correct way to do this for an mv field these days... &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | eval Field3=mvappend(Field1,Field2) | eval Field3=mvdedup(Field2) |
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or just &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | eval Field3=mvdedup(mvappend(Field1,Field2))
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;HR /&gt;

&lt;P&gt;What I suggest:&lt;/P&gt;

&lt;P&gt;.... | eval Field3=coalesce(Field1,Field2) | dedup Field3 | ...&lt;/P&gt;

&lt;P&gt;I'm wondering if the problem is still in place, I found this thread because I had this issue :).&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2016 13:32:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27682#M5407</guid>
      <dc:creator>janwilbert</dc:creator>
      <dc:date>2016-09-08T13:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27683#M5408</link>
      <description>&lt;P&gt;This will not work for multivalued fields merging (original requirement of the question) as Field1 will always have a value so Field3 will always be same as Field1. For newer versions (6.0+), mvappend is the way to go, for older versions, use the method described by Nick (Sideview).&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2016 16:20:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27683#M5408</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-09-08T16:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27684#M5409</link>
      <description>&lt;P&gt;Ah you're right, only works out for single valued fields. &lt;/P&gt;

&lt;P&gt;So it will be: &lt;BR /&gt;
.... | eval Field3=mvappend(Field1,Field2) | dedup Field3 | ...&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2016 16:28:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27684#M5409</guid>
      <dc:creator>janwilbert</dc:creator>
      <dc:date>2016-09-08T16:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27685#M5410</link>
      <description>&lt;P&gt;The dedup also works at removing duplicate events not duplicate values within mv field, so you'd use eval - mvdedup.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;.... | eval Field3=mvappend(Field1,Field2) | eval Field3=mvdedup(Field2) | ...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;OR just&lt;/P&gt;

&lt;P&gt;.... | eval Field3=mvdedup(mvappend(Field1,Field2))  | ...&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2016 16:33:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27685#M5410</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-09-08T16:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27686#M5411</link>
      <description>&lt;P&gt;I downvoted this post because doesn't work&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 22:38:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27686#M5411</guid>
      <dc:creator>landen99</dc:creator>
      <dc:date>2018-08-02T22:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27687#M5412</link>
      <description>&lt;P&gt;@landen99 - we've updated the top level answer to prepend the correct mv field answer that was down in the comment chain.  Please reverse your downvote.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 02:40:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27687#M5412</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2018-08-03T02:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: How do I combine mv fields into a new field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27688#M5413</link>
      <description>&lt;P&gt;Hi, see mvappends, works fine for me to agrregate 2 MV fileds into a new field..&lt;/P&gt;

&lt;P&gt;mvappend(X,...) &lt;BR /&gt;
This function takes an arbitrary number of arguments and returns a multivalue result of all the values. &lt;BR /&gt;
&lt;STRONG&gt;The arguments can be strings, multivalue fields or single value fields.&lt;/STRONG&gt; &lt;BR /&gt;
... | eval fullName=mvappend(initial_values, "middle value", last_values)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:12:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-combine-mv-fields-into-a-new-field/m-p/27688#M5413</guid>
      <dc:creator>mcantaloube</dc:creator>
      <dc:date>2020-09-29T21:12:59Z</dc:date>
    </item>
  </channel>
</rss>

