Hello,
I have written a splunk search which produces the following table:
from to parameter value
A C bla_1 111
B D bla_2 222
I want to modify that table into the following:
from to value
A bla_1 111
B bla_2 222
bla_1 C 111
bla_2 D 222
Would you have any ides on how to achieve this?
Thank you.
Try this...
(your search)
| eval myfan=mvrange(0,2)
| mvexpand myfan
| eval from=if(myfan=0,from,parameter)
| eval to=if(myfan=0,parameter,to)
| fields - parameter
Try this...
(your search)
| eval myfan=mvrange(0,2)
| mvexpand myfan
| eval from=if(myfan=0,from,parameter)
| eval to=if(myfan=0,parameter,to)
| fields - parameter
This has worked for me. Thank you.