Splunk Search
Highlighted

How do I consolidate the values returned from a database query into a single entry?

New Member

I am running search against a database that includes a username and ticket count (from our ticketing system). When the results come back, I have one user who is listed with multiple iterations of their name. For example:

Username Count
John Q User 5
John Quser 3
John User 6

These are all the same user, so I would like to combine the names into a single entry (as "John Q User"), and combine the counts for each entry to reflect (from the above example) the total count of 14.

Any help would be very much appreciated.

Tags (2)
0 Karma
Highlighted

Re: How do I consolidate the values returned from a database query into a single entry?

SplunkTrust
SplunkTrust

Is there another field (like email address) available from the database that would link common entries?

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: How do I consolidate the values returned from a database query into a single entry?

New Member

Unfortunately, no.

0 Karma
Highlighted

Re: How do I consolidate the values returned from a database query into a single entry?

New Member

I finally found this in another post"

http://answers.splunk.com/answers/61646/combining-multivalues-together-inside-a-field.html

Thanks for the response Rich!

0 Karma