Splunk Search

How do you combine two different values from a single field in a chart?

dojiepreji
Path Finder

Suppose I have a chart that counts the number of tickets done by a particular branch and displays them by priority.

Branch     Priority 1     Priority 2     Priority 3
branch1          2             3            5
branch2          1             2            2
branch3          3             4            3

What I want to do is combine branches 1 and 2 like so,

Branch           Priority 1     Priority 2     Priority 2
branch1/branch2        3            5               7
branch 3               3            4               3

I've tried replace, but it only renames the value of a single branch, and does not combine them.

I've also considered the coalesce command, but I could only use it when combining values coming from two different fields, not values coming from a single field.

Can anybody please point me in the right direction?

0 Karma

woodcock
Esteemed Legend

You can add this to the bottom of your existing search:

| eval Branch = if(Branch=="branch1" OR Branch=="branch2", "branch1/branch2", Branch)
| stats sum(*) AS * BY Branch

But you might get better performance if you move the eval line to be the first pipe after your base search string so that you do not need the stats line at all.

0 Karma

mayurr98
Super Champion

Hi @dojiepreji

you can try something like this:

<query for the chart>
| replace branch2 with branch1 in Branch 
| stats  sum(Priority*) as Priority* by Branch 
|  replace branch1 WITH branch1/branch2 in Branch

let me know if this helps!

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...