index=pear splunk_server_group=all sourcetype="chef_host_details" * host_tc="" pvc_grp="" NOT (host_is_dr=1) NOT (host_pod_is_live=0) earliest=-4h latest=now
| mvexpand roles{}| rename roles{} as toll list | search tolllist!="base" AND roleslist=*** | search tolllist=*
|dedup tolllist host | mvcombine tolllist| sort host tolllist| table host host_tc pvc_grp tolllist
this creates 4 column >> hosts >> host_tc,pvc_grp,tollist , I want to add another column before hosts and add manually some data .
... View more