Splunk Search

How to group together rows with similar names into a single row

sam1010
Explorer

sam1010_0-1629792492292.png

This is the table. How can I group together similar names into one entry and the count is added for both of them. For example 5-Mock Activity and 6-Mock activity should come in 1 row as "Mock Activity" and count for that field should be 19+5 i.e. 24  

Labels (5)
Tags (3)
0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@sam1010 

Just add this before stats command.

|rex field=environment "\d\s\-\s(?<environment>.*)"

KV 

0 Karma

sam1010
Explorer

yes it's working but the thing is there are many other fields which have similar names for example stage and staging, these two also need to be counted as one "Stage" how to do that?

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@sam1010 

You can replace those value by adding below search after rex command.

| replace "stag*" WITH "Stage" IN environment

 

KV 

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...