Splunk Search

How to merge 6 fields into one field, but still return unique values?

mansel_scheffel
Explorer

Hi,

I have 6 fields A B C D E F - Each have multiple unique numerical values.. I need to merge these unique numerical values into one new field.. basically to make it seem as if the 6 fields don't exist and only the one field containing all the numerical values the six fields have individually.. I then want to display the top 10 values of this newly created single field.

Any thoughts?

Thanks!

0 Karma
1 Solution

somesoni2
Revered Legend

Give this a try

your base search | eval commonfield=fieldA." ".fieldB." ".fieldC." ".fieldD." ".fieldE." ".fieldF." " | makemv commonfield | top commonfield showperc=f

View solution in original post

0 Karma

somesoni2
Revered Legend

Give this a try

your base search | eval commonfield=fieldA." ".fieldB." ".fieldC." ".fieldD." ".fieldE." ".fieldF." " | makemv commonfield | top commonfield showperc=f
0 Karma

mansel_scheffel
Explorer

Thanks for the help!

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...