- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How can we concatenate values from one field and put it in a new variable with commas.
e.g If I run a search , I get number of host in host field. I want to concatenate them all in one field separated by commas.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Do you mean you want to concatenate host values from all events collectively, not just from each individual event? If that's all you want, you can do
<your_search>
| stats values(host) AS host
| eval newfield = mvjoin(host, ",")
If you want a new field alongside other fields in events, use eventstats instead of stats
<your_search>
| eventstats values(host) AS newfield
| eval newfield = mvjoin(newfield, ",")
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


| eval newField=mvjoin(host, ",")
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This does not work. newField have the same values as host field. Its not concatenating.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Do you mean you want to concatenate host values from all events collectively, not just from each individual event? If that's all you want, you can do
<your_search>
| stats values(host) AS host
| eval newfield = mvjoin(host, ",")
If you want a new field alongside other fields in events, use eventstats instead of stats
<your_search>
| eventstats values(host) AS newfield
| eval newfield = mvjoin(newfield, ",")
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Sailesh6891 ,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated by all the contributors 😉
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


The values are *supposed* to be the same in the new field, except with commas added.
Please share sanitized examples of what results you have now and what you want.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Sailesh6891 ,
you could try somethng like this:
<your_search>
| stats values(host) AS host BY index
| nomv host
Ciao.
Giuseppe
