Splunk Search

accum command for field

maheshsat
Explorer

I have field called test, what would be out if use assume command

command: -- | accum test as test2 ( It will create test2 field but what would be the result).Thanks

test
1
90
3
4
5
6
8
1
1

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Just run this:

| makeresults | eval test = "1 90 3 4 5 6 8 1 1" | makemv test | mvexpand test | accum test as test2

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Just run this:

| makeresults | eval test = "1 90 3 4 5 6 8 1 1" | makemv test | mvexpand test | accum test as test2
0 Karma

maheshsat
Explorer

correction not assume command it is accum command.thanks

0 Karma
Get Updates on the Splunk Community!

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...