Splunk Search

How to combine information to a list

jenniferhao
Explorer

Hello,

I have a query to get the following lines:
element ID value temp (wanted)
ABC 1 false "false false false true true false"
ABC 4 true "false false false true true false"
ABC 2 false "false false false true true false"
ABC 3 false "false false false true true false"
ABC 5 true "false false false true true false"
ABC 6 false "false false false true true false"

Sort by ID and get their values list "false false false true true false" to a variable .
index="x" sourcetype="y"

| sort 0 element ID
| streamstats list(value) AS temp by element

How can I make the last list "false false false true true false" to temp as above?

Thanks

Tags (1)
0 Karma
1 Solution

mayurr98
Super Champion

try this:

index="x" sourcetype="y"
| sort 0 element ID
| eventstats list(value) AS temp by element

View solution in original post

0 Karma

mayurr98
Super Champion

try this:

index="x" sourcetype="y"
| sort 0 element ID
| eventstats list(value) AS temp by element
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...