Splunk Search

How to combine information to a list

jenniferhao
Explorer

Hello,

I have a query to get the following lines:
element ID value temp (wanted)
ABC 1 false "false false false true true false"
ABC 4 true "false false false true true false"
ABC 2 false "false false false true true false"
ABC 3 false "false false false true true false"
ABC 5 true "false false false true true false"
ABC 6 false "false false false true true false"

Sort by ID and get their values list "false false false true true false" to a variable .
index="x" sourcetype="y"

| sort 0 element ID
| streamstats list(value) AS temp by element

How can I make the last list "false false false true true false" to temp as above?

Thanks

Tags (1)
0 Karma
1 Solution

mayurr98
Super Champion

try this:

index="x" sourcetype="y"
| sort 0 element ID
| eventstats list(value) AS temp by element

View solution in original post

0 Karma

mayurr98
Super Champion

try this:

index="x" sourcetype="y"
| sort 0 element ID
| eventstats list(value) AS temp by element
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...