Splunk Search

How to compare the values from same fields?

saurabh_ha
Explorer

saurabh_ha_0-1664820432808.pngsaurabh_ha_0-1664820432808.png

I want to create the new_field when other values of field_1 is less than of first value.
Here in below example as 23 greater than other values then do sum of all which is 44.
for 10 is the smallest then its result is 10
for 11 there is one more value is less which is 10 then do sum with 10 then result is 21

Labels (1)
0 Karma
1 Solution

yuanliu
SplunkTrust
SplunkTrust

The following will work in Splunk 9 with the new multivalue mode in foreach.

| stats values(field_1) as field_1
| foreach field_1 mode=multivalue
    [eval new_field = mvappend(new_field, tostring(if(isnull(new_field), 0, max(new_field)) + <<ITEM>>))]
| eval zip = mvzip(field_1, new_field, ":")
| mvexpand zip
| eval zip = split(zip, ":")
| eval field_1 = mvindex(zip, 0), new_field = mvindex(zip, 1)

(If you need to access other fields in original search, modify "group by" clause or use eventstats as opposed to stats.)

I totally thought this could be solved with mvmap (no need for Splunk 9), but I couldn't get that to work.

View solution in original post

0 Karma

yuanliu
SplunkTrust
SplunkTrust

The following will work in Splunk 9 with the new multivalue mode in foreach.

| stats values(field_1) as field_1
| foreach field_1 mode=multivalue
    [eval new_field = mvappend(new_field, tostring(if(isnull(new_field), 0, max(new_field)) + <<ITEM>>))]
| eval zip = mvzip(field_1, new_field, ":")
| mvexpand zip
| eval zip = split(zip, ":")
| eval field_1 = mvindex(zip, 0), new_field = mvindex(zip, 1)

(If you need to access other fields in original search, modify "group by" clause or use eventstats as opposed to stats.)

I totally thought this could be solved with mvmap (no need for Splunk 9), but I couldn't get that to work.

0 Karma

saurabh_ha
Explorer

Thanks for the response.

It is working as expected  in our UAT as you mentioned

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...