Splunk Search

How to group together rows with similar names into a single row

sam1010
Explorer

sam1010_0-1629792492292.png

This is the table. How can I group together similar names into one entry and the count is added for both of them. For example 5-Mock Activity and 6-Mock activity should come in 1 row as "Mock Activity" and count for that field should be 19+5 i.e. 24  

Labels (4)
Tags (3)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@sam1010 

Just add this before stats command.

|rex field=environment "\d\s\-\s(?<environment>.*)"

KV 

0 Karma

sam1010
Explorer

yes it's working but the thing is there are many other fields which have similar names for example stage and staging, these two also need to be counted as one "Stage" how to do that?

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@sam1010 

You can replace those value by adding below search after rex command.

| replace "stag*" WITH "Stage" IN environment

 

KV 

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...