<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to split multipe values assigned to same fieldname into a single row table? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-split-multipe-values-assigned-to-same-fieldname-into-a/m-p/438506#M21241</link>
    <description>&lt;P&gt;@moksw,&lt;/P&gt;

&lt;P&gt;Try using multi value fields&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;      your search|stats values("Security ID") as ids,values("Account Name") as names,values("Account Domain") as domains
      |eval "Security ID1"=mvindex(ids,0),"Security ID2"=mvindex(ids,1)
      |eval "Account Name1"=mvindex(names,0),"Account Name2"=mvindex(names,1)
      |eval "Account Domain1"=mvindex(domains,0),"Account Domain2"=mvindex(domains,1)
      |table "Security ID1","Account Name1","Account Domain1","Security ID2","Account Name2","Account Domain2"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 19 Dec 2018 07:38:56 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2018-12-19T07:38:56Z</dc:date>
    <item>
      <title>how to split multipe values assigned to same fieldname into a single row table?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-split-multipe-values-assigned-to-same-fieldname-into-a/m-p/438505#M21240</link>
      <description>&lt;P&gt;How to write a search query to retrieve the two different values in Security ID, Account Name and Account Domain fields as a single row table? Result as:&lt;BR /&gt;
 "Security ID1 | Account Name1 | Account Domain1 | Security ID2 | Account Name2 | Account Domain2&lt;/P&gt;

&lt;P&gt;===========================================================&lt;BR /&gt;
An account was successfully logged on.&lt;/P&gt;

&lt;P&gt;Subject:&lt;BR /&gt;
    Security ID: SYSTEM&lt;BR /&gt;
    Account Name: DESKTOP-LLHJ389$&lt;BR /&gt;
    Account Domain: WORKGROUP&lt;BR /&gt;
    Logon ID: 0x3E7&lt;/P&gt;

&lt;P&gt;Logon Information:&lt;BR /&gt;
    Logon Type: 7&lt;BR /&gt;
    Restricted Admin Mode: -&lt;BR /&gt;
    Virtual Account: No&lt;BR /&gt;
    Elevated Token: No&lt;/P&gt;

&lt;P&gt;Impersonation Level: Impersonation&lt;/P&gt;

&lt;P&gt;New Logon:&lt;BR /&gt;
    Security ID: AzureAD\RandyFranklinSmith&lt;BR /&gt;
    Account Name: &lt;A href="mailto:rsmith@montereytechgroup.com"&gt;rsmith@montereytechgroup.com&lt;/A&gt;&lt;BR /&gt;
    Account Domain: AzureAD&lt;BR /&gt;
    Logon ID: 0xFD5113F&lt;BR /&gt;
    Linked Logon ID: 0xFD5112A&lt;BR /&gt;
    Network Account Name: -&lt;BR /&gt;
    Network Account Domain: -&lt;BR /&gt;
    Logon GUID: {00000000-0000-0000-0000-000000000000}&lt;/P&gt;

&lt;P&gt;Process Information:&lt;BR /&gt;
    Process ID: 0x30c&lt;BR /&gt;
    Process Name: C:\Windows\System32\lsass.exe&lt;/P&gt;

&lt;P&gt;Network Information:&lt;BR /&gt;
    Workstation Name: DESKTOP-LLHJ389&lt;BR /&gt;
    Source Network Address: -&lt;BR /&gt;
    Source Port: -&lt;/P&gt;

&lt;P&gt;Detailed Authentication Information:&lt;BR /&gt;
    Logon Process: Negotiat&lt;BR /&gt;
    Authentication Package: Negotiate&lt;BR /&gt;
    Transited Services: -&lt;BR /&gt;
    Package Name (NTLM only): -&lt;BR /&gt;
    Key Length: 0&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 17:32:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-split-multipe-values-assigned-to-same-fieldname-into-a/m-p/438505#M21240</guid>
      <dc:creator>moksw</dc:creator>
      <dc:date>2018-12-17T17:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: how to split multipe values assigned to same fieldname into a single row table?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-split-multipe-values-assigned-to-same-fieldname-into-a/m-p/438506#M21241</link>
      <description>&lt;P&gt;@moksw,&lt;/P&gt;

&lt;P&gt;Try using multi value fields&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;      your search|stats values("Security ID") as ids,values("Account Name") as names,values("Account Domain") as domains
      |eval "Security ID1"=mvindex(ids,0),"Security ID2"=mvindex(ids,1)
      |eval "Account Name1"=mvindex(names,0),"Account Name2"=mvindex(names,1)
      |eval "Account Domain1"=mvindex(domains,0),"Account Domain2"=mvindex(domains,1)
      |table "Security ID1","Account Name1","Account Domain1","Security ID2","Account Name2","Account Domain2"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 19 Dec 2018 07:38:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-split-multipe-values-assigned-to-same-fieldname-into-a/m-p/438506#M21241</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2018-12-19T07:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: how to split multipe values assigned to same fieldname into a single row table?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-split-multipe-values-assigned-to-same-fieldname-into-a/m-p/438507#M21242</link>
      <description>&lt;P&gt;I tried using below search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   index=wineventlog EventCode="4624" | stats values("Security ID") as ids,values("Account Name") as names,values("Account Domain") as domains
   |eval "Security ID1"=mvindex(ids,0),"Security ID2"=mvindex(ids,1)
   |eval "Account Name1"=mvindex(names,0),"Account Name2"=mvindex(names,1)
   |eval "Account Domain1"=mvindex(domains,0),"Account Domain2"=mvindex(domains,1)
   |table "Security ID1","Account Name1","Account Domain1","Security ID2","Account Name2","Account Domain2"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It outputs into as single row table. Its values keep changing in that row instead of writing into the next row when new event found. The time field is empty too.&lt;/P&gt;

&lt;P&gt;My required output should look like below:&lt;/P&gt;

&lt;P&gt;_time   Security ID1    Account Name 1  Account Domain1 Security ID2    Account Name 2  Account Domain2&lt;BR /&gt;
8.15am  System  DESKTOP-LLHJ389$    Workgroup   Randy &lt;A href="mailto:Franklin@montereytechgroup.com" target="_blank"&gt;Franklin@montereytechgroup.com&lt;/A&gt;    &lt;A href="mailto:rsmith@montereytechgroup.com" target="_blank"&gt;rsmith@montereytechgroup.com&lt;/A&gt;    New Workgroup&lt;BR /&gt;
8.17am  System  SG12345 Workgroup   helen_phua  Helen_phua  newDomain&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:27:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-split-multipe-values-assigned-to-same-fieldname-into-a/m-p/438507#M21242</guid>
      <dc:creator>moksw</dc:creator>
      <dc:date>2020-09-29T22:27:25Z</dc:date>
    </item>
  </channel>
</rss>

