Splunk Search

retrieve search fields as table

Contributor

I'm extracting a field say JVM (in props.conf). Now I want to write a search where i want JVM in one column and source in another. Just two columns. How can i achieve that?

0 Karma
1 Solution

Ultra Champion
* | dedup JVM source | table JVM source

this will create a table with the unique combinations of JVM and source.

* | dedup JVM | table JVM source

will find unique values of JVM, and table them along with the corresponding source value.

/kristian

View solution in original post

Ultra Champion
* | dedup JVM source | table JVM source

this will create a table with the unique combinations of JVM and source.

* | dedup JVM | table JVM source

will find unique values of JVM, and table them along with the corresponding source value.

/kristian

View solution in original post

Contributor

Thank you Kristian. this time im sure gonna tell your wife 😉

Influencer

*| table JVM source

Contributor

thank you 🙂

0 Karma

Influencer

... what kristian said 🙂

Contributor

Thank you. How can i get only unique values

0 Karma