Splunk Search

Create Single Field and Multifield Values Based on Same Fields

whitefang1726
Path Finder

Hi Splunkers,

How can I create a single value field based on multiple fields? Also, let's assume that the field names can be 

sample_1_country_1_name to sample_99_country_1_name and sample_1_country_1_name to sample_1_country_99_name. 

Example:

sample_1_country sample_2_country sample_99_country sample_37_country
Denmark Chile Thailand Croatia


Result
sample_country_name
Denmark, Chile, Thailand, Croatia

Thanks!

 

Labels (3)
0 Karma

whitefang1726
Path Finder

Nice, that works sir! Apologies, I just need to update the sample data to avoid oversharing of work items. We have a lot of this fields in our environment. Do you think this is possible using transforms and props? Thanks!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The problem with using made-up fake field names is that any proposed solution might not match your actual usecase. However, here is a solution using the names you provided - hopefully you will get the idea and be able to adapt it to your actual usecase

| makeresults format=csv data="sample_1_country,sample_2_country,sample_99_country,sample_37_country
Denmark,Chile,Thailand,Croatia"
| foreach sample_*_country
    [| eval sample_country_name=if(isnull(sample_country_name),<<FIELD>>,mvappend(sample_country_name,<<FIELD>>))]
| eval sample_country_name=mvjoin(sample_country_name,",")

 

 

Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...