Splunk Search

Append results in a single line.

Raging_Rags
Engager

| dbxquery connection="*"  query="select STOREENT_ID,count(*) O_C from table1 "
| appendcols
[| dbxquery connection="*" query="select count(*) P_S_T from table2 "
| join
[| dbxquery connection="*" query="select count(*) P_E_Y from table2"]
|join [dbxquery connection="*" query="select count(*) P_ACTIVE from table2 where status=1"]]

 

This my sample query, I want all the results in a single line. The value before append prints in a line and after append the values are printed in a new line.

Labels (5)
0 Karma

to4kawa
Ultra Champion

| stats values(*) as *

 

try this.

Raging_Rags
Engager

Actually its working but 2 rows get mixed up.

 

0 Karma

to4kawa
Ultra Champion

for mixed up field

| eval fieldname=mvjoin(mixed_up_field,",")

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...