All Apps and Add-ons

change the delimiter for multivalue fields

dominiquevocat
SplunkTrust
SplunkTrust

Is it possible to change the delimiter (currently , ) to something else?

I have multivalue fields where the content has "," in them.

Perhaps writing the cell multiline text would help?

0 Karma

dominiquevocat
SplunkTrust
SplunkTrust

I meant for the excel export. I need to reproduce it i fear - i might have mixed up two "issues". I get jumbled output tables with multivalue fields containing "," like LDAP DNs etc. The other issue is that i would like to modify the csv export result from scheduled searches etc. Sorry.

0 Karma

araitz
Splunk Employee
Splunk Employee

This is because the FR delimiter is ";"? And you do mean for the Excel Export app, not Splunk's native CSV Export?

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

See this document:

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Createandmaintainsearch-timefieldextrac...

The useful example here is:

[commalist] 
DELIMS = ", " 
FIELDS = field1, field2, field3 

I think this is exactly what you're looking for to solve the question you're asking.

0 Karma

dominiquevocat
SplunkTrust
SplunkTrust

nope
the values are DN from a directory and i just want to not use "," as the delimiter and not parse the values just output them to a multiline textfield.
I am hoping for the developer to chime in 🙂

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...