I have data being pushed onto Splunk in JSON format. What I am trying to do is combine events. For example, 2 events that have a common id should be merge onto one. So I have the following data: { studentid: 1234
studentGrade:{
Math:{ grade: "A"}
}
}
{ studentid: 1234
studentGrade:{
Physics:{ grade: "C"}
}
} As seen, I'd like to create the 2 events into 1 based on the studentId. To end up with a result like the following: Student Id Math Physics 1234 A C Thank you in advance, very new in Splunk and I found it difficult to merge events based on other requests Ids.
... View more