Splunk Search

Getting a comma separate string from values function within stats command

ramesh
Engager

When I extract the list of values of a field in stats command, the values appear in separate lines making the output sparse and ugly. Is it possible to get the values as a comma separated string so that everything sits in one line?

raoul
Path Finder

What you need is to use eval and then the mvjoin() function.

yoursearchhere |
stats values(myField) as myFieldValues by field2 |
eval myFieldValues=mvjoin(myFieldValues, ", ")

duartet
Path Finder

Yup that one works as intended! Thanks

0 Karma

lguinn2
Legend

You could do this by using the makemv command:

yoursearchhere | 
stats values(myField) as myFieldValues by field2 |
makemv delim="," myFieldValues

justdan23
Path Finder

Works for me in Splunk 8.0.2, but now I need to add a wildcard prefix and quotes to each value.

0 Karma

raoul
Path Finder

I downvoted this post because doesn't work

0 Karma

lguinn2
Legend

You are right, my apologies.

0 Karma

raoul
Path Finder

Actually, this just doesn't work. At any rate when I run such a query I do NOT get the values separated by commas.

Nor would one expect it to based on the documentation of the makemv command which says: Converts a single valued field into a multivalue field by splitting it on a simple string delimiter.

Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...