Splunk Search

mvindex - How to separate results?

dkeck
Influencer

Hi,

I have this code:

|rex max_match=0 field=values "value\":\"(?<example>(.*?))\""
|eval example=mvindex(example,0,1)

result is this :

*field*        *example*
action     failure success 

Is it possible to separate "failure" and "success" into 2 rows, so actually add a line break?
or at least add a ";" or ","?

Thank you

0 Karma
1 Solution

jeffland
SplunkTrust
SplunkTrust

There are probably many ways to do that. You could use mvexpand:

|rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" | mvexpand example

It should give you one line per value in your multivalue field while duplicating all other values.

View solution in original post

chimell
Motivator

Hi
try this search code

|rex max_match=0 field=values "value\":\"(?<example>(.*?))\""| eval example=split(example ," ") | mvexpand example 
0 Karma

ngatchasandra
Builder

Hi dkeck,

If you want to add " ," or ";" to use makemv command like follow:

  |rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" |eval example=mvindex(example,0,1) | makemv delim="," example

If you want to add linebreak you can try to use mvjoin function:

|rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" |eval example=mvindex(example,0,1) | eval example=mvjoin(example," ") | rex mode=sed field=example "s/,/\n/g"

mvjoin(example," ") because values of example are separated by space

0 Karma

jeffland
SplunkTrust
SplunkTrust

There are probably many ways to do that. You could use mvexpand:

|rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" | mvexpand example

It should give you one line per value in your multivalue field while duplicating all other values.

dkeck
Influencer

Thank you, but thats not what I want.

I want to keep the mvfield add just and some kind of separation to it, to make it more readable.

0 Karma

jeffland
SplunkTrust
SplunkTrust

Ah, I thought you wanted "two rows" in your table, but I assume you meant "two rows" inside your one result row, one for each value of your multivalue field.
That should be the case by default, so I'm not quite sure why your table has the two rex matches side by side. You could try this:

| rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" | eval example=replace(example, "\s", ";\s")

It should add a semicolon into your text.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...