Splunk Search

Lookup csv file different code with same meaning

indeed_2000
Motivator

Hi I have csv file that contain my errorcodes and meaning of them. I import this csv as lookup.

the problem is some codes have same meaning and when I get report show them separately

e.g

Here is the my csv:

code meaning

404    Page not found

402    Page not found

 

Current output:

Code            Meaning                         Count         

404            Page not found                  25                     

402            Page not found                  25

 

I need to consider them as one and count them like this:

Code                     Meaning                                  TotalCount

404, 402            Page not found                           50

 

FYI: if meaning are same consider they are same and able to count them

 

any idea?

Thanks

Labels (5)
Tags (5)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| lookup codes.csv
| stats values(code) as code count by meaning
| eval code=mvjoin(code,",")

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| lookup codes.csv
| stats values(code) as code count by meaning
| eval code=mvjoin(code,",")
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...