Splunk Search

What is a command that does the opposite of mvcombine?

Haybuck15
Explorer

So, I know MV Combine asks that you specify the one unique field in a set of results, and returns a multi-value entry that merges all the non-unique values. I want to do the opposite.

I have a table of events that contains a single non-unique field, and I want to merge the unique fields into a single event. For example, the original table might look something like this:

alt text

And I'm trying to turn it into something like this:

alt text

Does anyone have any insight into how I could do that?

0 Karma
1 Solution

493669
Super Champion

Try this:

...|stats values(*) as * by Hostname

It will give all unique values by Hostname

View solution in original post

493669
Super Champion

Try this:

...|stats values(*) as * by Hostname

It will give all unique values by Hostname

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...