Splunk Search

How to combine information to a list

jenniferhao
Explorer

Hello,

I have a query to get the following lines:
element ID value temp (wanted)
ABC 1 false "false false false true true false"
ABC 4 true "false false false true true false"
ABC 2 false "false false false true true false"
ABC 3 false "false false false true true false"
ABC 5 true "false false false true true false"
ABC 6 false "false false false true true false"

Sort by ID and get their values list "false false false true true false" to a variable .
index="x" sourcetype="y"

| sort 0 element ID
| streamstats list(value) AS temp by element

How can I make the last list "false false false true true false" to temp as above?

Thanks

Tags (1)
0 Karma
1 Solution

mayurr98
Super Champion

try this:

index="x" sourcetype="y"
| sort 0 element ID
| eventstats list(value) AS temp by element

View solution in original post

0 Karma

mayurr98
Super Champion

try this:

index="x" sourcetype="y"
| sort 0 element ID
| eventstats list(value) AS temp by element
0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...