Splunk Search

accum command for field

maheshsat
Explorer

I have field called test, what would be out if use assume command

command: -- | accum test as test2 ( It will create test2 field but what would be the result).Thanks

test
1
90
3
4
5
6
8
1
1

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Just run this:

| makeresults | eval test = "1 90 3 4 5 6 8 1 1" | makemv test | mvexpand test | accum test as test2

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Just run this:

| makeresults | eval test = "1 90 3 4 5 6 8 1 1" | makemv test | mvexpand test | accum test as test2
0 Karma

maheshsat
Explorer

correction not assume command it is accum command.thanks

0 Karma
Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...