Getting Data In

How can I parse 2 columns with text format together?

mklhs
Path Finder

I have 2 columns with text format (data 1 and data 2). One of the two columns is empty. I want to parse the 2 columns into a separate column together (data3).

alt text

P.S search | eval data3 = coalesce(data1, data2) it doesn't work

0 Karma
1 Solution

to4kawa
Ultra Champion
| makeresults
| eval _raw="time,\"data 1\",\"data 2\",\"data 3\"
2019-10-29 15:50:00.109+02:00,#user1#20191029155000#,
2019-10-29 15:51:00.109+02:00,,#user1#20191029155100#,
2019-10-29 15:52:00.109+02:00,#user1#20191029155200#,"
| multikv forceheader=1
| rename data_*_ as "data "*
| table time "data "*
`comment("this is sample data")`
| eval "data 3" = coalesce('data 1','data 2')

If you can describe the field name correctly, coalesce works.

View solution in original post

0 Karma

to4kawa
Ultra Champion
| makeresults
| eval _raw="time,\"data 1\",\"data 2\",\"data 3\"
2019-10-29 15:50:00.109+02:00,#user1#20191029155000#,
2019-10-29 15:51:00.109+02:00,,#user1#20191029155100#,
2019-10-29 15:52:00.109+02:00,#user1#20191029155200#,"
| multikv forceheader=1
| rename data_*_ as "data "*
| table time "data "*
`comment("this is sample data")`
| eval "data 3" = coalesce('data 1','data 2')

If you can describe the field name correctly, coalesce works.

0 Karma

HiroshiSatoh
Champion

Do I need to add it?

 | eval data3 = if(isnull(data1), data2,data1)
0 Karma

mklhs
Path Finder

Hello @HiroshiSatoh,

the column "data3" is empty. So, the column "data1" and "data2" were not parsed together. Do you know what it might be?

0 Karma

HiroshiSatoh
Champion

Is there a space in the field name?
If there is a space, please enclose it with a single quote.

data□1

'data□1'

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...