Splunk Search

How to create a table using dedup to show one entry for each application name and create a multivalue field?

stuart338
New Member

I have events that include an application name field and a uservalue field.

When i table the data by application and uservalue, i see each event individually thus meaning i get multiple pages of events with the same application name.

How can I have one entry for each application name and a multivalue field showing the uservalues?

EG: go from

application uservalue
app1            123456
app1            234567
app1            345678
app2            987654
app2            876543
app2            765432

and get :

application uservalue
app1          123456
              234567
              345678
app2          987654
              876543
              765432

It's probably something really easy, but I've stepped away from Splunk for awhile and forget even the easy stuff.

Thanks

0 Karma
1 Solution

dmaislin_splunk
Splunk Employee
Splunk Employee
source="Workbook1.csv" sourcetype="csv" | stats list(uservalue) as UserValue by application

alt text

View solution in original post

dmaislin_splunk
Splunk Employee
Splunk Employee
source="Workbook1.csv" sourcetype="csv" | stats list(uservalue) as UserValue by application

alt text

stuart338
New Member

See, i knew it was easy.. Thanks.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...