Splunk Search

How to merge value from multiple fields into a single field (Field = Value format)?

tehong
Explorer

Hi. 

I want to merge data from multiple fields into a single field.

If you have a table like the following

fieldA, fieldB, fieldC
------------------------------
valueA, valueB, valueC

The expected output is as follows. I want to combine them into a single field in the Field = Value format.

merge_data = "fieldA = valueA, fieldB = valueB, fieldC = valueC"

I think it can be done using multivalue OR foreach, but I don't know how to code it.

Thanks in advance!!

 

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| eval merge_data=","
| foreach field*
    [| eval merge_data=merge_data."<<FIELD>>"."=\"".trim(<<FIELD>>)."\","]
| eval merge_data=trim(merge_data,",")

View solution in original post

tehong
Explorer

Thanks perfect!!

ITWhisperer
SplunkTrust
SplunkTrust
| eval merge_data=","
| foreach field*
    [| eval merge_data=merge_data."<<FIELD>>"."=\"".trim(<<FIELD>>)."\","]
| eval merge_data=trim(merge_data,",")
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...