Splunk Search

How to get multiple values in a table

brentsinawski
Explorer

Hi everyone,
I am trying to create a table that lists multiple policy id's that shows all ports being used according to that policy ID. If I do a "| dedup policy_id | table policy_id dst_port src_port I get only one dst_port and one src_port. I'm looking to do a list of all the policy id with every port that policy id has used in a specific time. Hard to explain I guess.
I'm looking for

policy_id src_port dst_port
836 5622 5488 80 66 488 224 etc.

Any help would be extremely appreciated.
Thank you!!

Tags (2)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

You should try using stats with the values function:

| stats values(src_port) values(dst_port) by policy_id

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

You should try using stats with the values function:

| stats values(src_port) values(dst_port) by policy_id

sdaniels
Splunk Employee
Splunk Employee

There are a lot of options so it takes some time to see it all. I've seen at least 5%, so far of what Splunk can do.

0 Karma

brentsinawski
Explorer

Can't believe I couldn't figure that out. Your a life saver. Thank you very much!! Worked perfectly.

0 Karma
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...