Splunk Search

Substring of multivalues out ot multivalue field

geoffmartin
Engager

I'm trying to produce a multivalue field out of another multivalue field in my data model, and that's proven to be quite complicated. This is what I'm trying to achieve:

I have a multivalue field with application names, like:

Application:
   Word
   Excel
   PowerPoint

but since I have too many applications, I created a field submenu, in which you select the application first letter, and that filters the Application field. Then, out of the field above, I want to have one called "Submenu" with the following:

Submenu:
  W
  E
  P

And my tstats command do the rest on grouping and filtering. I tried to use substring but it doesn't work for multivalue fields, only the single-valued results of the field.

Any ideas?

0 Karma
1 Solution

somesoni2
Revered Legend

Try something like this

Your base search with field Application | eval SubMenu=Application | rex mode=sed field=SubMenu "s/(\w)(\w+)/\1/g" 

This will create a field SubMenu which will have same number of elements as Application and will contains just the first character from Application field values.

View solution in original post

somesoni2
Revered Legend

Try something like this

Your base search with field Application | eval SubMenu=Application | rex mode=sed field=SubMenu "s/(\w)(\w+)/\1/g" 

This will create a field SubMenu which will have same number of elements as Application and will contains just the first character from Application field values.

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...