Splunk Search

Merge raws based on common substring

gaglimax
Loves-to-Learn Lots

Hi,

Let's imagine I have those raws :

NameValue1Value2
foo12
foo1216
foodazd56
fooaoke43
foo5623
bar12
barjodpez74
barjo74
bar12575

 

I would like to create a search that gives :

Name

Value1

Value2

foo

foo12

foodazd

fooaoke

foo56

1

2

4

5

2

3

6

bar

barjodpez

barjo

bar125

1

7

2

4

5

 

So to explain with words, I want to merge raws based on the smallest common substring present in the Name column (here, foo and bar).

Thanks for your help.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...