Splunk Search

how can i concatenate values from separate logs?

ytl
Path Finder

i'm trying to generate a search where i can summarize its info into a table. specifically i'm trying to detect link flapping caused by hosts having the same mac address across many/same switches.

in the logs i get one entry for each occurrence, sometimes its across different hosts; so i group the logs with a transaction on the dvc_mac (which i have set up as a field extraction):

"is flapping between port" | transaction dvc_mac

what i would like is a table where i can concatenate all the hosts seen for that single dvc_mac address, eg:

mac_address  seen_on
dvc_mac      host1, host2...

is this possible?

0 Karma
1 Solution

Stephen_Sorkin
Splunk Employee
Splunk Employee

I think that you can do this more simply using stats:

"is flapping between port" | stats values(host) as seen_on by dvc_mac

View solution in original post

Stephen_Sorkin
Splunk Employee
Splunk Employee

I think that you can do this more simply using stats:

"is flapping between port" | stats values(host) as seen_on by dvc_mac

Stephen_Sorkin
Splunk Employee
Splunk Employee

It's hard for me to read the structure of this in comment form. Ask another question, add a link to it and we'll address it there.

0 Karma

ytl
Path Finder

woohoo! worked a treat; thanks Stephen!

to extend the question a little;

1) what if i wanted to also include the interfaces seen on the host? i have a multivalue field called 'int' such that i would like

mac_address  seen_on
dvc_mac      hostA (intA1, intA2), hostB (intB1, intB2)...

2) if i wanted a frequency count of each dvc_mac

mac_address  seen_on                  count
dvc_mac      hostA (intA1, intA2)...  4

cheers,

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...