Splunk Enterprise

How to copy and insert row?

Kirthika
Path Finder

For the below table, whenever a comparison_result column value is equal to "not equal", it should copy the corresponding whole row value and insert before that row by changing curr_row value alone to "Turn on".

_time ID curr_row comparison_result
2015-02-16T03:24:57.182+05:30 19 Turn on equal
2015-02-16T03:24:58.869+05:30 19 1245 equal
2015-02-16T03:25:09.179+05:30 19 1245 equal
2015-02-16T03:25:12.394+05:30 19 1245 equal
2015-02-16T03:25:24.571+05:30 19 1245 equal
2015-02-16T05:30:41.956+05:30 19 1245 equal
2015-02-16T06:02:36.635+05:30 19 1245 equal
2015-02-16T06:23:23.446+05:30 20 Turn on not equal
2015-02-16T06:23:24.608+05:30 20 7656 equal
2015-02-16T06:40:46.619+05:30 20 7690 not equal
2015-02-16T06:46:59.594+05:30 20 8783 equal
Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this.

| eval row=if(comparison_result=="not equal" AND curr_row!="Turn on",mvrange(0,2),null())
| mvexpand row
| eval curr_row=if(row==0,"Turn on",curr_row)
| fields - row

Your dummy data is a bit suspect (again!) imho, so I have assumed you only want to duplicate the row if curr_row is not already "Turn on"

Btw, shouldn't the last row also be "not equal"? (Suspect data!)

View solution in original post

Kirthika
Path Finder

Thanks.  It works perfectly

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this.

| eval row=if(comparison_result=="not equal" AND curr_row!="Turn on",mvrange(0,2),null())
| mvexpand row
| eval curr_row=if(row==0,"Turn on",curr_row)
| fields - row

Your dummy data is a bit suspect (again!) imho, so I have assumed you only want to duplicate the row if curr_row is not already "Turn on"

Btw, shouldn't the last row also be "not equal"? (Suspect data!)

Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...