I have data being pushed onto Splunk in JSON format. What I am trying to do is combine events. For example, 2 events that have a common id should be merge onto one. So I have the following data:
{ studentid: 1234
studentGrade:{
Math:{ grade: "A"}
}
}
{ studentid: 1234
studentGrade:{
Physics:{ grade: "C"}
}
}
As seen, I'd like to create the 2 events into 1 based on the studentId. To end up with a result like the following:
Student Id | Math | Physics |
1234 | A | C |
Thank you in advance, very new in Splunk and I found it difficult to merge events based on other requests Ids.