Splunk Search

How to merge cells in Splunk

spl10
Explorer

I want to merge the cells in column S.No and share the output to the requestor.

The only ask is Splunk should take all the values seperated in different colours and send three different emails.

Ex    S.No.

1

2

3

4

5

6

7

8

9

10

11

12

I should send emails to 

S.No 

1

4

9Capture.PNG

Capture1.PNG

 

Labels (1)
0 Karma
1 Solution

yuanliu
SplunkTrust
SplunkTrust

You need to mind the basics of posing an answerable question: clearly illustrate data input (in text table), illustrate desired output (also in text unless it is a graphic visualization), and explain the logic in clear language.   It is really unclear what is the relationship between these field values.  

If I have to speculate, Appname, and requestor are always paired, S.No and host are always paired.  Is this correct?  Based on this, I made up the following mock data:

AppnameS.Nohostlogtyperequestorsource
A1ghisomelog[email protected]somelog.jkl
A1ghisomelog[email protected]somelog.klm
A1ghisomelog[email protected]somelog.lmn
B2hijsomelog[email protected]somelog.klm
B2hijsomelog[email protected]somelog.jkl
C3ijksomelog[email protected]somelog.lmn
C3ijksomelog[email protected]somelog.aaa
A4xyzsomelog[email protected]somelog.opq
A4xyzsomelog[email protected]somelog.opq
A4xyzsomelog[email protected]somelog.bbb
B5wxysomelog[email protected]somelog.rst
B5wxysomelog[email protected]somelog.uvw
C6vwxsomelog[email protected]somelog.uvw
C6vwxsomelog[email protected]somelog.rst
C6vwxsomelog[email protected]somelog.opq
A7aaasomelog[email protected]somelog.klm
A7aaasomelog[email protected]somelog.lmn
A7aaasomelog[email protected]somelog.jkl
B8bbbsomelog[email protected]somelog.klm
C9cccsomelog[email protected]somelog.lmn
C9cccsomelog[email protected]somelog.aaa
C9cccsomelog[email protected]somelog.bbb
A10hijsomelog[email protected]somelog.aaa
B11jklsomelog[email protected]somelog.aaa
B11jklsomelog[email protected]somelog.bbb
B11jklsomelog[email protected]somelog.ccc
C12ijksomelog[email protected]somelog.abc
C12ijksomelog[email protected]somelog.ccc

As @ITWhisperer says, Splunk is not a spreadsheet.  You cannot have cell merge and such.  But if you really want to simulate the effect, you can do something like this:

 

 

| stats values(source) as source by Appname logtype requestor S.No host
| rename S.No as S_No
| eval source = mvjoin(source, ", ")
| tojson S_No host source
| stats values(_raw) as _raw by Appname requestor logtype
| eval host = mvmap(_raw, spath(_raw, "host"))
| eval S.No = mvmap(_raw, spath(_raw, "S_No"))
| eval source = mvmap(_raw, spath(_raw, "source"))
| table S.No Appname requestor logtype source

 

 

Result from the above mock data is

S.No
Appnamerequestorlogtype
source
1
10
4
7
A[email protected]somelog
somelog.jkl, somelog.klm, somelog.lmn
somelog.aaa
somelog.bbb, somelog.opq
somelog.jkl, somelog.klm, somelog.lmn
11
2
5
8
B[email protected]somelog
somelog.aaa, somelog.bbb, somelog.ccc
somelog.jkl, somelog.klm
somelog.rst, somelog.uvw
somelog.klm
12
3
6
9
C[email protected]somelog
somelog.abc, somelog.ccc
somelog.aaa, somelog.lmn
somelog.opq, somelog.rst, somelog.uvw
somelog.aaa, somelog.bbb, somelog.lmn

Is this something you are looking for?

Here is mock data emulation:

 

 

| makeresults format=csv data="S.No, requestor, Appname, host, logtype, source
1, [email protected], A, ghi, somelog, somelog.jkl
1, [email protected], A, ghi, somelog, somelog.klm
1, [email protected], A, ghi, somelog, somelog.lmn
2, [email protected], B, hij, somelog, somelog.klm
2, [email protected], B, hij, somelog, somelog.jkl
3, [email protected], C, ijk, somelog, somelog.lmn
3, [email protected], C, ijk, somelog, somelog.aaa
4, [email protected], A, xyz, somelog, somelog.opq
4, [email protected], A, xyz, somelog, somelog.opq
4, [email protected], A, xyz, somelog, somelog.bbb
5, [email protected], B, wxy, somelog, somelog.rst
5, [email protected], B, wxy, somelog, somelog.uvw
6, [email protected], C, vwx, somelog, somelog.uvw
6, [email protected], C, vwx, somelog, somelog.rst
6, [email protected], C, vwx, somelog, somelog.opq
7, [email protected], A, aaa, somelog, somelog.klm
7, [email protected], A, aaa, somelog, somelog.lmn
7, [email protected], A, aaa, somelog, somelog.jkl
8, [email protected], B, bbb, somelog, somelog.klm
9, [email protected], C, ccc, somelog, somelog.lmn
9, [email protected], C, ccc, somelog, somelog.aaa
9, [email protected], C, ccc, somelog, somelog.bbb
10, [email protected], A, hij, somelog, somelog.aaa
11, [email protected], B, jkl, somelog, somelog.aaa
11, [email protected], B, jkl, somelog, somelog.bbb
11, [email protected], B, jkl, somelog, somelog.ccc
12, [email protected], C, ijk, somelog, somelog.abc
12, [email protected], C, ijk, somelog, somelog.ccc"
``` data emulation above ```

 

View solution in original post

yuanliu
SplunkTrust
SplunkTrust

You need to mind the basics of posing an answerable question: clearly illustrate data input (in text table), illustrate desired output (also in text unless it is a graphic visualization), and explain the logic in clear language.   It is really unclear what is the relationship between these field values.  

If I have to speculate, Appname, and requestor are always paired, S.No and host are always paired.  Is this correct?  Based on this, I made up the following mock data:

AppnameS.Nohostlogtyperequestorsource
A1ghisomelog[email protected]somelog.jkl
A1ghisomelog[email protected]somelog.klm
A1ghisomelog[email protected]somelog.lmn
B2hijsomelog[email protected]somelog.klm
B2hijsomelog[email protected]somelog.jkl
C3ijksomelog[email protected]somelog.lmn
C3ijksomelog[email protected]somelog.aaa
A4xyzsomelog[email protected]somelog.opq
A4xyzsomelog[email protected]somelog.opq
A4xyzsomelog[email protected]somelog.bbb
B5wxysomelog[email protected]somelog.rst
B5wxysomelog[email protected]somelog.uvw
C6vwxsomelog[email protected]somelog.uvw
C6vwxsomelog[email protected]somelog.rst
C6vwxsomelog[email protected]somelog.opq
A7aaasomelog[email protected]somelog.klm
A7aaasomelog[email protected]somelog.lmn
A7aaasomelog[email protected]somelog.jkl
B8bbbsomelog[email protected]somelog.klm
C9cccsomelog[email protected]somelog.lmn
C9cccsomelog[email protected]somelog.aaa
C9cccsomelog[email protected]somelog.bbb
A10hijsomelog[email protected]somelog.aaa
B11jklsomelog[email protected]somelog.aaa
B11jklsomelog[email protected]somelog.bbb
B11jklsomelog[email protected]somelog.ccc
C12ijksomelog[email protected]somelog.abc
C12ijksomelog[email protected]somelog.ccc

As @ITWhisperer says, Splunk is not a spreadsheet.  You cannot have cell merge and such.  But if you really want to simulate the effect, you can do something like this:

 

 

| stats values(source) as source by Appname logtype requestor S.No host
| rename S.No as S_No
| eval source = mvjoin(source, ", ")
| tojson S_No host source
| stats values(_raw) as _raw by Appname requestor logtype
| eval host = mvmap(_raw, spath(_raw, "host"))
| eval S.No = mvmap(_raw, spath(_raw, "S_No"))
| eval source = mvmap(_raw, spath(_raw, "source"))
| table S.No Appname requestor logtype source

 

 

Result from the above mock data is

S.No
Appnamerequestorlogtype
source
1
10
4
7
A[email protected]somelog
somelog.jkl, somelog.klm, somelog.lmn
somelog.aaa
somelog.bbb, somelog.opq
somelog.jkl, somelog.klm, somelog.lmn
11
2
5
8
B[email protected]somelog
somelog.aaa, somelog.bbb, somelog.ccc
somelog.jkl, somelog.klm
somelog.rst, somelog.uvw
somelog.klm
12
3
6
9
C[email protected]somelog
somelog.abc, somelog.ccc
somelog.aaa, somelog.lmn
somelog.opq, somelog.rst, somelog.uvw
somelog.aaa, somelog.bbb, somelog.lmn

Is this something you are looking for?

Here is mock data emulation:

 

 

| makeresults format=csv data="S.No, requestor, Appname, host, logtype, source
1, [email protected], A, ghi, somelog, somelog.jkl
1, [email protected], A, ghi, somelog, somelog.klm
1, [email protected], A, ghi, somelog, somelog.lmn
2, [email protected], B, hij, somelog, somelog.klm
2, [email protected], B, hij, somelog, somelog.jkl
3, [email protected], C, ijk, somelog, somelog.lmn
3, [email protected], C, ijk, somelog, somelog.aaa
4, [email protected], A, xyz, somelog, somelog.opq
4, [email protected], A, xyz, somelog, somelog.opq
4, [email protected], A, xyz, somelog, somelog.bbb
5, [email protected], B, wxy, somelog, somelog.rst
5, [email protected], B, wxy, somelog, somelog.uvw
6, [email protected], C, vwx, somelog, somelog.uvw
6, [email protected], C, vwx, somelog, somelog.rst
6, [email protected], C, vwx, somelog, somelog.opq
7, [email protected], A, aaa, somelog, somelog.klm
7, [email protected], A, aaa, somelog, somelog.lmn
7, [email protected], A, aaa, somelog, somelog.jkl
8, [email protected], B, bbb, somelog, somelog.klm
9, [email protected], C, ccc, somelog, somelog.lmn
9, [email protected], C, ccc, somelog, somelog.aaa
9, [email protected], C, ccc, somelog, somelog.bbb
10, [email protected], A, hij, somelog, somelog.aaa
11, [email protected], B, jkl, somelog, somelog.aaa
11, [email protected], B, jkl, somelog, somelog.bbb
11, [email protected], B, jkl, somelog, somelog.ccc
12, [email protected], C, ijk, somelog, somelog.abc
12, [email protected], C, ijk, somelog, somelog.ccc"
``` data emulation above ```

 

spl10
Explorer

Thank you so for the responses @bowesmana @ITWhisperer and a special thanks to @yuanliu.

I really apologize for posting the requirement in an unclear manner, I was extremely fatigued yet desperately needed to find the solution.

Honestly saying I wasn't confident that I would receive the response so quickly and precise.

I sincerely appreciate the community and individuals like you make this as a wonderful forum for discussion.

To be part of this community is an honor.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Splunk is not a spreadsheet, having said that you can use the stats command to "merge cells"

| stats min('S No') as "S No" list(*) as * by Appname
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Before this stats command also add this

| filldown Appname

so that empty Appname rows will adopt the name from above

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...