Merge Multiple Values into a Single Field


1 comment

  • Avatar
    Joseph Plunkett

    I got this figured out and I'll post the answer here in case it helps someone else. 


    | count dst_ip, dst_port  // this dedupes the values
    | now() as _messagetime  //Need this for transactionize
    | transactionize dst_ip (merge dst_ip takeFirst, dstport join with ", ") //Formats the table
    | fields - _messagetime



    Comment actions Permalink

Please sign in to leave a comment.