Splunk Search

Lookup csv file different code with same meaning

indeed_2000
Motivator

Hi I have csv file that contain my errorcodes and meaning of them. I import this csv as lookup.

the problem is some codes have same meaning and when I get report show them separately

e.g

Here is the my csv:

code meaning

404    Page not found

402    Page not found

 

Current output:

Code            Meaning                         Count         

404            Page not found                  25                     

402            Page not found                  25

 

I need to consider them as one and count them like this:

Code                     Meaning                                  TotalCount

404, 402            Page not found                           50

 

FYI: if meaning are same consider they are same and able to count them

 

any idea?

Thanks

Labels (5)
Tags (5)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| lookup codes.csv
| stats values(code) as code count by meaning
| eval code=mvjoin(code,",")

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| lookup codes.csv
| stats values(code) as code count by meaning
| eval code=mvjoin(code,",")
0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...