Merge Multiple Values into a Single Field

Comments

1 comment

  • Avatar
    Joseph Plunkett

    I got this figured out and I'll post the answer here in case it helps someone else. 

     

    _sourceCategory=<YourSrcCategoryHere>
    | count dst_ip, dst_port  // this dedupes the values
    | now() as _messagetime  //Need this for transactionize
    | transactionize dst_ip (merge dst_ip takeFirst, dstport join with ", ") //Formats the table
    | fields - _messagetime

     

     

    1
    Comment actions Permalink

Please sign in to leave a comment.