Splunk Search
Highlighted

Combining two field into one output

Path Finder

Hi,

Below is the query which generates the table output.

index=abc sourcetype=report | table companyid , companyname

OUTPUT

companyid companyname

published1 microsoft
published3 google
Published4 apple

Can someone please help me on how can I get the companyid , companyname is one field. something like below:

Result
published1,microsoft
published23,google
published4,apple

0 Karma
Highlighted

Re: Combining two field into one output

Champion

Try this!

(your search)|eval companyjoin=companyid+companyname|table companyjoin
published1microsoft

(your search)|eval companyjoin=companyid+":"+companyname|table companyjoin
published1:microsoft