Splunk Search

How to group by country and concatenate the cities into one row?

maximusdm
Communicator

giving the folowing scenario:

...
| table Country City Population

>     Country       City        Population
>     Spain     Madrid      2,456,000
>     Spain     Barcelona   3,222,000
>     Spain     Valencia    1,111,000
>     England       London      9,222,000
>     England       Oxford      1,211,000

How can I display the same results but grouping by Country and concatenating the cities and population?
Something like:

Spain   Madrid(2,456,000), Barcelona(3,222,000), Valencia(1,111,000)
England London(9,222,000), Oxford(1,211,000)

Thanks for the help

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Try like this

... | table Country City Population
| eval Population=City."(".Population.")"
| stats values(Population) as Population by Country delim=","
| nomv Population

View solution in original post

somesoni2
Revered Legend

Try like this

... | table Country City Population
| eval Population=City."(".Population.")"
| stats values(Population) as Population by Country delim=","
| nomv Population

maximusdm
Communicator

wow thanks I was doing stats by Country but not getting anywhere. Never heard of nomv command.
Thank you so much.

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...