Splunk Search

How do you combine two different values from a single field in a chart?

dojiepreji
Path Finder

Suppose I have a chart that counts the number of tickets done by a particular branch and displays them by priority.

Branch     Priority 1     Priority 2     Priority 3
branch1          2             3            5
branch2          1             2            2
branch3          3             4            3

What I want to do is combine branches 1 and 2 like so,

Branch           Priority 1     Priority 2     Priority 2
branch1/branch2        3            5               7
branch 3               3            4               3

I've tried replace, but it only renames the value of a single branch, and does not combine them.

I've also considered the coalesce command, but I could only use it when combining values coming from two different fields, not values coming from a single field.

Can anybody please point me in the right direction?

0 Karma

woodcock
Esteemed Legend

You can add this to the bottom of your existing search:

| eval Branch = if(Branch=="branch1" OR Branch=="branch2", "branch1/branch2", Branch)
| stats sum(*) AS * BY Branch

But you might get better performance if you move the eval line to be the first pipe after your base search string so that you do not need the stats line at all.

0 Karma

mayurr98
Super Champion

Hi @dojiepreji

you can try something like this:

<query for the chart>
| replace branch2 with branch1 in Branch 
| stats  sum(Priority*) as Priority* by Branch 
|  replace branch1 WITH branch1/branch2 in Branch

let me know if this helps!

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...