Splunk Search

How to combine multiple fields?

zkenaga
New Member

I have multiple fields with the name name_zz_(more after this)

How would I be able to merge all of the like tests into one field?

Tags (3)
0 Karma
1 Solution

somesoni2
Revered Legend

You want to merge values (concatenate values) OR each event will have single field but different name but you want to create a common name field?

0 Karma

zkenaga
New Member

I am looking to join all the names together and have them report as one name.

0 Karma

zkenaga
New Member

right now I have

name_zz_1
name_zz_2
name_zz_3

I would like to have those combined to just report as name_zz

0 Karma

somesoni2
Revered Legend

So basically, right now you've to do like this to see all values?

...some search | table ..some fields.. name_zz_1 name_zz_2 name_zz_3

and you want to do like

...some search | table ..some fields.. name_zz

Where name_zz will contain values of all 3 (or any number of fields) name_zz_N fields?

It's generally easier for us if you can post some sample values and corresponding expected output.

0 Karma

somesoni2
Revered Legend

If its the first case (multiple fields to be combined into one), try this

...some search.. | eval name_zz="" | foreach name_zz_* [| eval name_zz=coalesce('<<FIELD>>'.",","").name_zz] | fields - name_zz_*
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...