Splunk Search

how to get the first(_raw) when i have split my pattern which were separated by pipe "|" using eval and split command.

annamareddi
New Member

unique_exception= pattern1|pattern2|pattern3
all these three patterns(1,2,3) are tagged to unique number 111.
eval temp=split(unique_exception, "|")|stats values(temp) by temp
i am getting output as follows
111 - pattern1
111 - pattern2
111 - pattern3

now how to get the first event for these individual events (pattern1 and pattern2 and pattern3) separately.

Tags (1)
0 Karma

sundareshr
Legend

See if this helps

... | makemv unique_exception delim="|" | mvexpand unique_exception | stats first(_raw) as first_occurrence by unique_exception
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Please check this

eval temp=split(unique_exception, "|")|stats first(_time) as _time values(temp) by temp 

There is a good reference for Functions for stats in the docs. - http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Commonstatsfunctions

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...