Splunk Search

Combine table rows

lgroot
Explorer

Hi everyone,

I've got a question about a query i have made:

index=security-mijnssp "View rendered = /error.jspx" OR "Er is een fout opgetreden op de JSF pagina"  | rex "BSN=(?P<BSN>[^<]+) View" | rex "INFO  n.s.m.w.l(?P<INFO>[^<]+)"|rex "ERROR n.s.m.w.l(?P<ERROR>[^<]+)"|  table INFO,BSN, ERROR, _time

Is it possible to combine the results of this query in one row?
So that the INFO,BSN,ERROR and time are in one row?

alt text

0 Karma
1 Solution

somesoni2
Revered Legend

You would be able to combine this if they have a common field that can correlate them. From the example/screenshot, only common field I can see is _time, so my answer is based on _time, change the field if there are any other common fields.

Update
Actually BSN is the common field, so updating it to BSN

 index=security-mijnssp "View rendered = /error.jspx" OR "Er is een fout opgetreden op de JSF pagina"  | rex "BSN=(?P<BSN>[^<]+) View" | rex "INFO  n.s.m.w.l(?P<INFO>[^<]+)"|rex "ERROR n.s.m.w.l(?P<ERROR>[^<]+)"|  table INFO,BSN, ERROR, _time |stats values(*) as * by BSN

View solution in original post

0 Karma

somesoni2
Revered Legend

You would be able to combine this if they have a common field that can correlate them. From the example/screenshot, only common field I can see is _time, so my answer is based on _time, change the field if there are any other common fields.

Update
Actually BSN is the common field, so updating it to BSN

 index=security-mijnssp "View rendered = /error.jspx" OR "Er is een fout opgetreden op de JSF pagina"  | rex "BSN=(?P<BSN>[^<]+) View" | rex "INFO  n.s.m.w.l(?P<INFO>[^<]+)"|rex "ERROR n.s.m.w.l(?P<ERROR>[^<]+)"|  table INFO,BSN, ERROR, _time |stats values(*) as * by BSN
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...