Splunk Search

How to group each full iteration into single fields?

ABSplunker93
Engager

I have a stats table with output in the below format:

Device                          Timestamp        Action

some value                some value.             1

some value              some value.              2

..                     ..                                .. 

some value                some value              10

some value                 some value               1

some value              some value.                  2

..                     ..                                .. 

some value                some value              10

 

So, the action column repeats the pattern after a certain number of iterations. How to group these into single fields, that is, each full iteration should be stored as a mv field.

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The stats command doesn't create arbitrary patterns the results.  Either the pattern exists in the data or it's introduced in the query.  You may need to add or change the by clause in the stats command.  For more specifics, please share the SPL and a sanitized data sample.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...