Splunk Search

compare two multivalue fields to get unique values in a third field

architkhanna
Path Finder

I have 2 multivalue collumns like below,giving two rows for example:

Collumn 1      collumn 2
A                           A
B                           C
C


A                            A
B                            B
A
C
C


i want a third column like this(having values of collumn1 which are in collumn 2)

Collumn 1      collumn 2        collumn 3
A                           A                                 A
B                           C                                 C
C


A                            A                                 A
B                            B                                 B
A                                                                A
C
C
 
Please note,Collumn 1 can be empty also.

Thanks in Advance.

Labels (2)
0 Karma

to4kawa
Ultra Champion

| makeresults
| eval Col1=split("ABC",""),Col2=split("AC","")
| appendpipe [eval Col1=split("ABACC",""), Col2=split("AB","")]
| streamstats count as session
| mvexpand Col1
| eval result=if(match(Col2,Col1),Col1,NULL)
| stats list(Col1) as Col1 values(Col2) as Col2 list(result) as result by session
| fields - session

0 Karma

architkhanna
Path Finder

I am trying not to use mvexapnd in splunk8
Also I cannot use "makeresult" command since it has to be the first command in my search,which in my case is not.

0 Karma

to4kawa
Ultra Champion

I don't know what your query is.
It's a query that everyone can do.

0 Karma

architkhanna
Path Finder

Query is what I have asked for and the sample values I have provided.
If you can understand well and good ,else Thanks for your time.

Tags (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...