Splunk Search

accum command for field

maheshsat
Explorer

I have field called test, what would be out if use assume command

command: -- | accum test as test2 ( It will create test2 field but what would be the result).Thanks

test
1
90
3
4
5
6
8
1
1

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Just run this:

| makeresults | eval test = "1 90 3 4 5 6 8 1 1" | makemv test | mvexpand test | accum test as test2

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Just run this:

| makeresults | eval test = "1 90 3 4 5 6 8 1 1" | makemv test | mvexpand test | accum test as test2
0 Karma

maheshsat
Explorer

correction not assume command it is accum command.thanks

0 Karma
Get Updates on the Splunk Community!

SOC Modernization: How Automation and Splunk SOAR are Shaping the Next-Gen Security ...

Security automation is no longer a luxury but a necessity. Join us to learn how Splunk ES and SOAR empower ...

Ask It, Fix It: Faster Investigations with AI Assistant in Observability Cloud

  Join us in this Tech Talk and learn about the recently launched AI Assistant in Observability Cloud. With ...

Index This | How many sides does a circle have?

  March 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...