Splunk Search

After Eventstats two events are clubbed to a single row. how to ignore second event

DataOrg
Builder

Below column has two values after eventstats command. i want to ignore the second events "Passed" from the column "Value". i tried Mvexpand  to spilt but i totally dont want since i cant use dedup to remove duplicates

 

premranjithj_0-1643341919606.png

 

Labels (2)
Tags (2)
0 Karma
1 Solution

johnhuang
Motivator

You can use mvindex to replace itself with the first value

| eval Value=MVINDEX(Value, 0)

 

View solution in original post

0 Karma

johnhuang
Motivator

You can use mvindex to replace itself with the first value

| eval Value=MVINDEX(Value, 0)

 

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...