|
I'm indexing a CSV that appears like the following in its raw form:
etc.. In Splunk both "Filenum" and "String" are correctly being extracted as field names. I'd like to spit out a table that automatically groups Filenums with two or more matching Strings. For example, Filenum 1 & 3 can be grouped together since they both have Strings abc & xyz. Sample desired output:
Any ideas? Thanks! |