Splunk Search

How can i create new fields with data from two different multi value fields?

mauricio_sandov
Explorer

I need to break out log data from two separate multi-value fields into single value fields. Here is what data looks like:

Screenshot 2023-09-19 at 12.00.11 PM.png

 Each line of data from "participants{}.object_value" corresponds to the line in "participants{}.role" and I would like named victims and offender fields.  I dont understand how to use the mv commands to expand the data from two different fields and then combine them into new fields.

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Once multi-value fields are expanded, any relationship among them is lost.  They need to be combined into a new field before expansion.

...
| eval new_field = mvzip("participants{}.object_value", "participants{}.role")
| mvexpand new_field
| eval new_field = split(new_field, ",")
| eval object_value = mvindex(new_field, 0), role = mvindex(new_field, 1)

The mvzip function combines two multi-value fields, separating them with a comma.  The split function later on breaks the field on the comma.  If you have more than two fields to combine, use nested mvzip functions.

| eval new_field = mvzip(field1, mvzip(field2, mvzip(field3, field4)))

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Once multi-value fields are expanded, any relationship among them is lost.  They need to be combined into a new field before expansion.

...
| eval new_field = mvzip("participants{}.object_value", "participants{}.role")
| mvexpand new_field
| eval new_field = split(new_field, ",")
| eval object_value = mvindex(new_field, 0), role = mvindex(new_field, 1)

The mvzip function combines two multi-value fields, separating them with a comma.  The split function later on breaks the field on the comma.  If you have more than two fields to combine, use nested mvzip functions.

| eval new_field = mvzip(field1, mvzip(field2, mvzip(field3, field4)))

 

---
If this reply helps you, Karma would be appreciated.

mauricio_sandov
Explorer

Thank you this worked and did what I needed

mauricio_sandov
Explorer

I will give this a shot to see what I get. thx

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...