Splunk Search

How to merge value from multiple fields into a single field (Field = Value format)?

tehong
Explorer

Hi. 

I want to merge data from multiple fields into a single field.

If you have a table like the following

fieldA, fieldB, fieldC
------------------------------
valueA, valueB, valueC

The expected output is as follows. I want to combine them into a single field in the Field = Value format.

merge_data = "fieldA = valueA, fieldB = valueB, fieldC = valueC"

I think it can be done using multivalue OR foreach, but I don't know how to code it.

Thanks in advance!!

 

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| eval merge_data=","
| foreach field*
    [| eval merge_data=merge_data."<<FIELD>>"."=\"".trim(<<FIELD>>)."\","]
| eval merge_data=trim(merge_data,",")

View solution in original post

tehong
Explorer

Thanks perfect!!

ITWhisperer
SplunkTrust
SplunkTrust
| eval merge_data=","
| foreach field*
    [| eval merge_data=merge_data."<<FIELD>>"."=\"".trim(<<FIELD>>)."\","]
| eval merge_data=trim(merge_data,",")
Get Updates on the Splunk Community!

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...

Hunt Smarter, Not Harder: Discover New SPL “Recipes” in Our Threat Hunting Webinar

Are you ready to take your threat hunting skills to the next level? As Splunk community members, you know the ...