Splunk Search

How to group by and concat column values?

spl_1991
Engager

Given the below scenario:

base search| table service_name,status,count

Service_name

Status

Count

serviceA

500_INTERNAL _ERROR

10

serviceA

404_NOT_FOUND

4

serviceB

404_NOT_FOUND

1

serviceC

500_INTERNAL_ERROR

2

ServiceC

404_NOT_FOUND

5

serviceD

206_PARTIAL_ERROR

1

 

How can I display the results with group by service_name and the result as below table:

Service_name

Status

Count

serviceA

500_INTERNAL _ERROR, 404_NOT_FOUND

14

serviceB

404_NOT_FOUND

1

serviceC

500_INTERNAL_ERROR, 404_NOT_FOUND

7

serviceD

206_PARTIAL_ERROR

1

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @spl_1991,

please try this:

base search
| stats values(status) AS status sum(count) AS count BY service_name

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @spl_1991,

please try this:

base search
| stats values(status) AS status sum(count) AS count BY service_name

Ciao.

Giuseppe

spl_1991
Engager

Hi @gcusello ,

Thanks a lot and it worked....grazie!!

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...