You can't combine Splunk columns inside a Splunk table, but you can make second and subsequent duplicates clear, like this example | makeresults format=csv data="VM,col1,col2
vm1,car,sedan
vm2,car,s...
See more...
You can't combine Splunk columns inside a Splunk table, but you can make second and subsequent duplicates clear, like this example | makeresults format=csv data="VM,col1,col2
vm1,car,sedan
vm2,car,sedan
vm3,plane,Priv
vm4,bike,Fazer
vm5,bike,thunder"
| stats values(col*) as col* by VM
| streamstats count as c1 by col1
| streamstats count as c2 by col2
| eval col1=if(c1>1, null(), col1)
| eval col2=if(c2>1, null(), col2)
| fields - c1 c2