Splunk Search

How to merge 2 lines in a table into one

mah
Builder

Hi,

I have a table like this : 

testcount
test AA1
test AB2
test C3

 

I want to merge "test AA" and "test AB" which will give me a count of 3 together.

What I want :

testcount
test A3
test C3

 

How Can I do that ?

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The best answer will depend on the nature of the test field, but this is one way to do it.

... | eval test = substr(test,1,6)
| stats count by test
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...