Assume we have the following splunk records:
S=1 T=abcd demoval=hello
T=abcd anotherdemo=anothwerhello
T=abcd lastdemo=lastworld
S=1 is mandatory in the search, this initial record must match.
Question: How would i group the T value/key pair to get S,demoval,anotherdemo
and lastdemo together in the output?
Thanks...
The transaction command can group these events together into one event based on a common field:
Then you can create a table with rows that have the common T values alongside the S, demoval, anotherdemo, and lastdemo values there were previously part of separate events.
http://docs.splunk.com/Documentation/Splunk/6.0.2/SearchReference/Transaction
Thanks.
There is one point missing - the initial S=* condition.
Another sample:
S=1 T=abcd demoval=hello
S=xx T=abcd anotherdemo=anothwerhello
S=YY T=abcd lastdemo=lastworld
The T key value should be grouped while the initial search condition must start with S=1
followed
by any other values (xx or yy)
The transaction command can group these events together into one event based on a common field:
Then you can create a table with rows that have the common T values alongside the S, demoval, anotherdemo, and lastdemo values there were previously part of separate events.
http://docs.splunk.com/Documentation/Splunk/6.0.2/SearchReference/Transaction
Thanks, the table staement made it.