Archive
Highlighted

field combination does not work properly

New Member

Hi,
I have the following search on splunk indexer.
Although field "a" and "b" return results, field "steps" does not return stable results.(only one or zero result is returned).
thanks

sourcetype="F5:iRule:WebAccess"|sort -reqelapsedtime|head 3|stats count by url clientaddress reqelapsedtime servername|stats sum(count) as count list(url) as a list(servername) as b by servername | eval steps=b."-".a| fields steps count

Tags (2)
0 Karma
Highlighted

Re: field combination does not work properly

Legend

eval won't like doing string concatenations on multivalued fields. It does that on single-valued fields only.

0 Karma
Highlighted

Re: field combination does not work properly

Communicator

You can use mvexpand before your field concatenation.

View solution in original post

Highlighted

Re: field combination does not work properly

New Member

Thanks for your recommendation.
It solved my issue.

0 Karma