Splunk Search

Lookup csv file different code with same meaning

indeed_2000
Motivator

Hi I have csv file that contain my errorcodes and meaning of them. I import this csv as lookup.

the problem is some codes have same meaning and when I get report show them separately

e.g

Here is the my csv:

code meaning

404    Page not found

402    Page not found

 

Current output:

Code            Meaning                         Count         

404            Page not found                  25                     

402            Page not found                  25

 

I need to consider them as one and count them like this:

Code                     Meaning                                  TotalCount

404, 402            Page not found                           50

 

FYI: if meaning are same consider they are same and able to count them

 

any idea?

Thanks

Labels (5)
Tags (5)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| lookup codes.csv
| stats values(code) as code count by meaning
| eval code=mvjoin(code,",")

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| lookup codes.csv
| stats values(code) as code count by meaning
| eval code=mvjoin(code,",")
0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...