Alerting

How do I group similar values together?

srizan
Path Finder
source=*prod*
 | dedup SRV JAVAVER
 | stats count(SRV) by JAVAVER

This would generate report with all of the Java Versions.

I visualized using PieChart but I am only interested in seeing the chart with JAVAVER grouped as Java 18, Java 17 & Java19 instead of Java1801, Java1802, and so on.

Bascially, I want to group something like this only for the Pie Chart if possible:

JAVAVER=Java19* -> Java19
 JAVAVER=Java18* -> Java18
 JAVAVER=Java17* -> Java17
Tags (1)
0 Karma
1 Solution

anthonymelita
Contributor

You can use the substring function before your stats statement.
| eval JAVAVER=substr(JAVAVER,0,6)

View solution in original post

anthonymelita
Contributor

You can use the substring function before your stats statement.
| eval JAVAVER=substr(JAVAVER,0,6)

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...