Splunk Search

How to list chosen fields in one field?

nathanluke1986
Engager

Hello,

I am trying to list fields I have selected into a single field to display in a dashboard.

Currently trying   | eval Details = mvappend('src', 'dest')  but this only lists the values what I am trying to achieve is listing field name and value for example.

src=192.168.0.1

dest=192.168.0.2

etc 

etc

 

any help appreciated.

thanks

 

 

Labels (2)
0 Karma

smurf
Communicator

Hi,

you can concatenate strings together with eval.

| eval src="src=" + src

This would result in src field containing "src=192.168.0.1".  For a few fields, this would be easy to do.

 

smurf

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...