Alerting

How do I group similar values together?

srizan
Path Finder
source=*prod*
 | dedup SRV JAVAVER
 | stats count(SRV) by JAVAVER

This would generate report with all of the Java Versions.

I visualized using PieChart but I am only interested in seeing the chart with JAVAVER grouped as Java 18, Java 17 & Java19 instead of Java1801, Java1802, and so on.

Bascially, I want to group something like this only for the Pie Chart if possible:

JAVAVER=Java19* -> Java19
 JAVAVER=Java18* -> Java18
 JAVAVER=Java17* -> Java17
Tags (1)
0 Karma
1 Solution

anthonymelita
Contributor

You can use the substring function before your stats statement.
| eval JAVAVER=substr(JAVAVER,0,6)

View solution in original post

anthonymelita
Contributor

You can use the substring function before your stats statement.
| eval JAVAVER=substr(JAVAVER,0,6)

Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...