Splunk Search

How to group together rows with similar names into a single row

sam1010
Explorer

sam1010_0-1629792492292.png

This is the table. How can I group together similar names into one entry and the count is added for both of them. For example 5-Mock Activity and 6-Mock activity should come in 1 row as "Mock Activity" and count for that field should be 19+5 i.e. 24  

Labels (5)
Tags (3)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@sam1010 

Just add this before stats command.

|rex field=environment "\d\s\-\s(?<environment>.*)"

KV 

0 Karma

sam1010
Explorer

yes it's working but the thing is there are many other fields which have similar names for example stage and staging, these two also need to be counted as one "Stage" how to do that?

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@sam1010 

You can replace those value by adding below search after rex command.

| replace "stag*" WITH "Stage" IN environment

 

KV 

Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of Splunk APM’s and Splunk RUM’s streaming infrastructure in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...