<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Separate multi-value field in individual fields in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344774#M39833</link>
    <description>&lt;P&gt;Ahhbone last thing. Check example 3 in the splunk mvexpand command doc&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Mvexpand"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Mvexpand&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Mar 2018 23:39:25 GMT</pubDate>
    <dc:creator>damiensurat</dc:creator>
    <dc:date>2018-03-09T23:39:25Z</dc:date>
    <item>
      <title>How do I separate multi-value field in individual fields?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344772#M39831</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;I have the following syntax that extract multiple values for the same fields in an event.&lt;/P&gt;
&lt;P&gt;This is the query:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;index=.... | rex max_match=100 "(?&amp;lt;connBlock&amp;gt;\d+)\s+(?&amp;lt;connector&amp;gt;[\d\w]+)\s+Located\s+at\s+STA:\s*(?&amp;lt;sta_coord&amp;gt;[\d\w[^,]+)
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;For this query I get the following fields for each event:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;connBlock = [500 600 700 800 ...] and stat_coord [A345 A3422 B2434 ...]
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Those events also have a field called testNum which looks like "AFKE-232322".&lt;/P&gt;
&lt;P&gt;I want to create a table like this:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;testNUM            connBlock         stat_coord
AFKE-232322        500               A345
AFKE-232322        600               A3422
AFKE-232322        700               B2434
AFKE-232322        800               C745
... I also have different tests
AFBE-228322        500               A345
AFBE-228322        600               D3422
AFCE-005322        700               B2434
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;When I try to do a table, I get the table below, and the stat_coord, connBlock appear in the same row than the testNum.&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;testNUM            connBlock         stat_coord
AFKE-232322        500               A345
                   600               A3422
                   700               B2434
                   800               C745
AFBE-228322        500               A345
                   600               D3422
AFCE-005322        500               B2434
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;The reason for separating the fields is that I want to do a query like the one below and get the sta_coord or the connector based on a testNum and connBlock of an event.&lt;/P&gt;
&lt;P&gt;index=.... | search testNum=AFKE-232322 connBlock=600&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 19:05:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344772#M39831</guid>
      <dc:creator>edrivera3</dc:creator>
      <dc:date>2023-05-02T19:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Separate multi-value field in individual fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344773#M39832</link>
      <description>&lt;P&gt;Hi edrivera3.  I've experienced these types of scenarios before and man. What a doozie. You may want to try to use the mvexpand on those fields if they are already considered multivalue. In some scenarios you may need to make the field a mv field first using the makemv command and then piping out to mvexpand. Try your search| mvexpand connBlock |mvexpand stat_coord.  Here a link to a similar mv solution which may help as well: &lt;A href="https://answers.splunk.com/answers/25653/mvexpand-multiple-multi-value-fields.html"&gt;https://answers.splunk.com/answers/25653/mvexpand-multiple-multi-value-fields.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If this doesn't work let me know and id be happy to further assist. Happy splunking!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 23:34:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344773#M39832</guid>
      <dc:creator>damiensurat</dc:creator>
      <dc:date>2018-03-09T23:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Separate multi-value field in individual fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344774#M39833</link>
      <description>&lt;P&gt;Ahhbone last thing. Check example 3 in the splunk mvexpand command doc&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Mvexpand"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Mvexpand&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 23:39:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344774#M39833</guid>
      <dc:creator>damiensurat</dc:creator>
      <dc:date>2018-03-09T23:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Separate multi-value field in individual fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344775#M39834</link>
      <description>&lt;P&gt;Thanks. I think this is the solution, but the results gets truncated.  I actually have 5 different multi-value fields.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 00:13:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344775#M39834</guid>
      <dc:creator>edrivera3</dc:creator>
      <dc:date>2018-03-10T00:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Separate multi-value field in individual fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344776#M39835</link>
      <description>&lt;P&gt;Did you use limit=0 argument.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;limit
Syntax: limit=
Description: Specify the number of values of  to use for each input event.
Default: 0, or no limit
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 10 Mar 2018 00:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344776#M39835</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2018-03-10T00:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Separate multi-value field in individual fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344777#M39836</link>
      <description>&lt;P&gt;Hi edrivera3,&lt;/P&gt;

&lt;P&gt;You can use mvexpand with eval to do this. &lt;/P&gt;

&lt;P&gt;Here is the sample query for you.&lt;/P&gt;

&lt;P&gt;Your base query&lt;BR /&gt;
| eval tagged=mvzip(testNUM, connBlock) &lt;BR /&gt;
| mvexpand tagged &lt;BR /&gt;
| makemv tagged delim="," &lt;BR /&gt;
| eval testNUM=mvindex(tagged,0) &lt;BR /&gt;
| eval connBlock=mvindex(tagged,1) &lt;BR /&gt;
| table *&lt;/P&gt;

&lt;P&gt;Hopefully this will get you what your expecting to do.&lt;/P&gt;

&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 08:34:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344777#M39836</guid>
      <dc:creator>fz</dc:creator>
      <dc:date>2018-03-12T08:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Separate multi-value field in individual fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344778#M39837</link>
      <description>&lt;P&gt;damientsurat: Your solution is correct and it's the same as the one provided by fz. Do you want me accept your answer? If so, please write an answer with the solution. If you are not interested I'm going to accept fz's answer.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Mar 2018 18:41:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/344778#M39837</guid>
      <dc:creator>edrivera3</dc:creator>
      <dc:date>2018-03-12T18:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Separate multi-value field in individual fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/580488#M47550</link>
      <description>&lt;P&gt;Thanks a lot &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; !&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 16:54:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/580488#M47550</guid>
      <dc:creator>mihai_T</dc:creator>
      <dc:date>2022-01-10T16:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Separate multi-value field in individual fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/642044#M52441</link>
      <description>&lt;P&gt;Thanks so much for this! Also fixed my similar issues! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 17:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/How-do-I-separate-multi-value-field-in-individual-fields/m-p/642044#M52441</guid>
      <dc:creator>clehw</dc:creator>
      <dc:date>2023-05-02T17:32:11Z</dc:date>
    </item>
  </channel>
</rss>

