Hi,
I have a query which gives GroupName and its members in the below format
GroupName member
Domain Admins CN=firstname1\, lastname1 P0,OU=P0-Accounts,OU=test OU
CN=firstname2\, lastname2 P1,OU=P1-Accounts,OU=test OU
CN=firstname3\, lastname3 P3,OU=P3-Accounts,OU=test OU
And im trying to extract it in multiple events like below seperately for each and every member
GroupName member
Domain Admins CN=firstname1\, lastname1 P0,OU=P0-Accounts,OU=test OU
Domain Admins CN=firstname2\, lastname2 P1,OU=P1-Accounts,OU=test OU
Domain Admins CN=firstname3\, lastname3 P3,OU=P3-Accounts,OU=test OU
Does mvexpand work for you?
"your search"
|mvexpand member
Does mvexpand work for you?
"your search"
|mvexpand member
@renjith_nair No mvexpand didnt work
Ok , so why didn't work, is it not a multi value field? or can you share the search which results in the existing state?
Hey thanks now I realised my mistake i have used mvexpand on my lookup so it didnt work and now I tried mvexpand on actual index and sourcetype its working fine