Splunk Search

i want the output in the below format. please answer my query how to achieve it.

AyushiSrivas
Loves-to-Learn

i want the output in the below format :-

Input as below:-

host           sql instance           db name

abc              sql1                          db1

abc               sql1                          db2

abc               sql2                           db123

abc               sql2                           db1234

xyz               xyzsql1                    db11

xyz                xyzsql2                   db321

xyz                xyzsql2                    db123

xyz                xyzsql2                    db1234

www             wwwsql1              db123

www            wwwsql1                db1234

outpu as below:-

host           sql instance           db name

abc              sql1                          db1

                                                         db2

 abc              sql2                        db123

                                                         db1234

xyz               xyzsql1                    db11

xyz                xyzsql2                   db321

                                                          db123

                                                          db1234

www             wwwsql1              db123

                                                          db1234

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

| stats values('db name') as "db name" by host 'sql instance'
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...