Splunk Search

How to use eval min and mvcombine ip for events grouped by two or three other fields?

Communicator

Hello!
How can I, for example, eval min(_time) an mvcombine ip for event grouped by two or three other fields?
Thank you in advance!

Tags (4)
0 Karma

Influencer

try this

Some search terms | eventstats min(_time) as MinTime by Field_1, Field_2| mvcombine IP_Addr

If you intention is to combine multivalue field among a group of identical events, see this also

Some search terms | stats min(_time) as "Min Time", values(Ip_addr) as "IP Addresses" by Field_1, Field_2
0 Karma