Hi, i need index time and host time to repeat for each data for host, printedA_epoch & printedb_epoch, how can i achieve it
Thanks,
Karuna
If you have Splunk 8 (for mvmap) you can do this
| makeresults
| eval r=mvrange(1,15)
| mvexpand r
| eval printedA_epoch=now() - (random() % 604800)
| eval printedB_epoch=now() - (random() % 604800)
| eval indtime=now()
| eval host="XP03"
| stats values(printedA_epoch) as printedA_epoch values(printedB_epoch) as printedB_epoch by host indtime
| table host printedA_epoch printedB_epoch indtime
| eval comment="Your data is created up to here - so now duplicate host and indtime as required"
| eval h=mvrange(1,mvcount(printedA_epoch) + 1)
| eval host=mvmap(h,host), indtime=mvmap(h,indtime)
| fields - h comment
Hope this helps
Thank you @bowesmana but am using splunk 7.0.1 where 'mvmap' function is not supported or undefined, could you please provide me an alternative command.
Try this
| makeresults
| eval r=mvrange(1,15)
| mvexpand r
| eval printedA_epoch=now() - (random() % 604800)
| eval printedB_epoch=now() - (random() % 604800)
| eval indtime=now()
| eval host="XP03"
| stats values(printedA_epoch) as printedA_epoch values(printedB_epoch) as printedB_epoch by host indtime
| table host printedA_epoch printedB_epoch indtime
| eval comment="Your data is created up to here - so now duplicate host and indtime as required"
| eval tmp=mvzip(printedA_epoch, printedB_epoch, ",")
| fields - printedA_epoch printedB_epoch comment
| mvexpand tmp
| rex field=tmp "(?<printedA_epoch>\d+),(?<printedB_epoch>\d+)"
| fields - tmp
| stats list(*) as *
Thanks for your valuable time
| stats list(*) as * it displays all my field in the indexed data i have to display only limited columns
CustomerjobId,printedA_epoch,printedB_epoch,indexdatetime
as i have to do difference of A and B epoc with indexedtime epoc
Replace the list(*) as * with
list(a) as a list(b) as b list(c) as c
for the columns you need
Hi @bowesmana , really appreciate your multiple solution, after implementing am getting Aepoch vales as 0000 instead of its value..
Thanks,
Karuna