I have events that include an application name field and a uservalue field.
When i table the data by application and uservalue, i see each event individually thus meaning i get multiple pages of events with the same application name.
How can I have one entry for each application name and a multivalue field showing the uservalues?
EG: go from
and get :
It's probably something really easy, but I've stepped away from Splunk for awhile and forget even the easy stuff.
source="Workbook1.csv" sourcetype="csv" | stats list(uservalue) as UserValue by application
View solution in original post
See, i knew it was easy.. Thanks.