Splunk Search

Lookup csv file different code with same meaning

indeed_2000
Builder

Hi I have csv file that contain my errorcodes and meaning of them. I import this csv as lookup.

the problem is some codes have same meaning and when I get report show them separately

e.g

Here is the my csv:

code meaning

404    Page not found

402    Page not found

 

Current output:

Code            Meaning                         Count         

404            Page not found                  25                     

402            Page not found                  25

 

I need to consider them as one and count them like this:

Code                     Meaning                                  TotalCount

404, 402            Page not found                           50

 

FYI: if meaning are same consider they are same and able to count them

 

any idea?

Thanks

Labels (5)
Tags (5)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| lookup codes.csv
| stats values(code) as code count by meaning
| eval code=mvjoin(code,",")

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| lookup codes.csv
| stats values(code) as code count by meaning
| eval code=mvjoin(code,",")
0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>