Splunk Search

What is a command that does the opposite of mvcombine?

Haybuck15
Explorer

So, I know MV Combine asks that you specify the one unique field in a set of results, and returns a multi-value entry that merges all the non-unique values. I want to do the opposite.

I have a table of events that contains a single non-unique field, and I want to merge the unique fields into a single event. For example, the original table might look something like this:

alt text

And I'm trying to turn it into something like this:

alt text

Does anyone have any insight into how I could do that?

0 Karma
1 Solution

493669
Super Champion

Try this:

...|stats values(*) as * by Hostname

It will give all unique values by Hostname

View solution in original post

493669
Super Champion

Try this:

...|stats values(*) as * by Hostname

It will give all unique values by Hostname

Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...