Splunk Search

What is a command that does the opposite of mvcombine?

Haybuck15
Explorer

So, I know MV Combine asks that you specify the one unique field in a set of results, and returns a multi-value entry that merges all the non-unique values. I want to do the opposite.

I have a table of events that contains a single non-unique field, and I want to merge the unique fields into a single event. For example, the original table might look something like this:

alt text

And I'm trying to turn it into something like this:

alt text

Does anyone have any insight into how I could do that?

0 Karma
1 Solution

493669
Super Champion

Try this:

...|stats values(*) as * by Hostname

It will give all unique values by Hostname

View solution in original post

493669
Super Champion

Try this:

...|stats values(*) as * by Hostname

It will give all unique values by Hostname

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...