This topic describes how to use the function in the Splunk Data Stream Processor.
Groups a stream of records by one or more field(s) and returns a grouped stream. Because
Key_by outputs a
GroupedBy stream, this function must be used in conjunction with
Merge Events. This function does not show metrics in the UI.
Function Input/Output Schema
- Function Input
- This function takes in collections of records with schema R.
- Function Output
- This function outputs records with schema V, grouped on schema K.
- Syntax: <fields>
- Description: The names of the fields to group records.
- Example in Canvas View: source, host
Examples of common use cases follow. The following examples assume that you are in the SPL View.
When working in the SPL View, you can write the function by using the syntax shown in each use case.
1. Group records by source
...| key_by keys=source |...
2. Group records by source and host
...| key_by keys=[source, host] |...
This documentation applies to the following versions of Splunk® Data Stream Processor: 1.1.0, 1.2.0, 1.2.1-patch02, 1.2.1, 1.2.2-patch02, 1.2.4, 1.2.5, 1.3.0, 1.3.1