Splunk Search

How to merge value from multiple fields into a single field (Field = Value format)?

tehong
Explorer

Hi. 

I want to merge data from multiple fields into a single field.

If you have a table like the following

fieldA, fieldB, fieldC
------------------------------
valueA, valueB, valueC

The expected output is as follows. I want to combine them into a single field in the Field = Value format.

merge_data = "fieldA = valueA, fieldB = valueB, fieldC = valueC"

I think it can be done using multivalue OR foreach, but I don't know how to code it.

Thanks in advance!!

 

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| eval merge_data=","
| foreach field*
    [| eval merge_data=merge_data."<<FIELD>>"."=\"".trim(<<FIELD>>)."\","]
| eval merge_data=trim(merge_data,",")

View solution in original post

tehong
Explorer

Thanks perfect!!

ITWhisperer
SplunkTrust
SplunkTrust
| eval merge_data=","
| foreach field*
    [| eval merge_data=merge_data."<<FIELD>>"."=\"".trim(<<FIELD>>)."\","]
| eval merge_data=trim(merge_data,",")
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...