Splunk Search

How to get multiple values in a table

brentsinawski
Explorer

Hi everyone,
I am trying to create a table that lists multiple policy id's that shows all ports being used according to that policy ID. If I do a "| dedup policy_id | table policy_id dst_port src_port I get only one dst_port and one src_port. I'm looking to do a list of all the policy id with every port that policy id has used in a specific time. Hard to explain I guess.
I'm looking for

policy_id src_port dst_port
836 5622 5488 80 66 488 224 etc.

Any help would be extremely appreciated.
Thank you!!

Tags (2)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

You should try using stats with the values function:

| stats values(src_port) values(dst_port) by policy_id

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

You should try using stats with the values function:

| stats values(src_port) values(dst_port) by policy_id

sdaniels
Splunk Employee
Splunk Employee

There are a lot of options so it takes some time to see it all. I've seen at least 5%, so far of what Splunk can do.

0 Karma

brentsinawski
Explorer

Can't believe I couldn't figure that out. Your a life saver. Thank you very much!! Worked perfectly.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...