@clarkedayne in order for the community to assist you better kindly provide more details on what you currently have and what is your issue. Adding a screenshot/mock/anonymized data and current Splunk search will help!
While posting data/code make sure you mask out any sensitive information and use the code button (101010
or sortcut key Ctrl+K
)
How do the three events differ? By time? If so, then use the timechart
command.
have you dove into this doc?
https://docs.splunk.com/Documentation/Splunk/7.2.5/Search/Parsemultivaluefields