<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How multivalue of field can be extracted in the below mentioned event , all the events are in the same format, any solution/query ? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-multivalue-of-field-can-be-extracted-in-the-below-mentioned/m-p/486158#M136027</link>
    <description>&lt;P&gt;That is the whole point of &lt;CODE&gt;multikv&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|makeresults | eval _raw="Filesystem                      Type Size Used Avail UsePct MountedOn
/dev/mapper/rootvg-rootlv       ext3 6.0G 4.3G  1.4G    77% /
/dev/sda1                       ext3 194M  78M  107M    43% /boot
/dev/mapper/rootvg-home_lv      ext3 2.0G 528M  1.4G    28% /local_home
/dev/mapper/rootvg-opt_lv       ext3 6.0G 1.2G  4.5G    21% /opt
/dev/mapper/rootvg-tmp_lv       ext3 2.0G 230M  1.7G    13% /tmp
/dev/mapper/rootvg-usr_lv       ext3 2.0G 116M  1.8G     7% /usr/local
/dev/mapper/rootvg-var_lv       ext3 4.0G 1.4G  2.4G    37% /var
/dev/mapper/rootvg-history_lv   ext3 2.0G  68M  1.9G     4% /history_logs
/dev/mapper/rootvg-itm_lv       ext3 3.0G 608M  2.3G    22% /opt/IBM/ITM
/dev/mapper/appvg-apps_lv       ext3  32G 177M   30G     1% /apps
/dev/mapper/appvg-usr_apigee_lv ext3 197G 485M  187G     1% /usr/apigee
/dev/mapper/appvg-apilogs_lv    ext3  20G 173M   19G     1% /apilogs
/dev/mapper/appvg-Introscope_lv ext3 3.0G  69M  2.8G     3% /Introscope
/dev/mapper/rootvg-venafi_lv    ext4 976M 1.3M  924M     1% /venafi
/dev/mapper/appvg-opt_apigee_lv ext4 197G 8.9G  178G     5% /opt/apigee"
| multikv forceheader=1 copyattrs=t
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Sun, 17 Nov 2019 01:30:34 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-11-17T01:30:34Z</dc:date>
    <item>
      <title>How multivalue of field can be extracted in the below mentioned event , all the events are in the same format, any solution/query ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-multivalue-of-field-can-be-extracted-in-the-below-mentioned/m-p/486156#M136025</link>
      <description>&lt;P&gt;Filesystem                                          Type              Size        Used       Avail      UsePct    MountedOn&lt;BR /&gt;
/dev/mapper/rootvg-rootlv                           ext3              6.0G        4.3G        1.4G         77%    /&lt;BR /&gt;
/dev/sda1                                           ext3              194M         78M        107M         43%    /boot&lt;BR /&gt;
/dev/mapper/rootvg-home_lv                          ext3              2.0G        528M        1.4G         28%    /local_home&lt;BR /&gt;
/dev/mapper/rootvg-opt_lv                           ext3              6.0G        1.2G        4.5G         21%    /opt&lt;BR /&gt;
/dev/mapper/rootvg-tmp_lv                           ext3              2.0G        230M        1.7G         13%    /tmp&lt;BR /&gt;
/dev/mapper/rootvg-usr_lv                           ext3              2.0G        116M        1.8G          7%    /usr/local&lt;BR /&gt;
/dev/mapper/rootvg-var_lv                           ext3              4.0G        1.4G        2.4G         37%    /var&lt;BR /&gt;
/dev/mapper/rootvg-history_lv                       ext3              2.0G         68M        1.9G          4%    /history_logs&lt;BR /&gt;
/dev/mapper/rootvg-itm_lv                           ext3              3.0G        608M        2.3G         22%    /opt/IBM/ITM&lt;BR /&gt;
/dev/mapper/appvg-apps_lv                           ext3               32G        177M         30G          1%    /apps&lt;BR /&gt;
/dev/mapper/appvg-usr_apigee_lv                     ext3              197G        485M        187G          1%    /usr/apigee&lt;BR /&gt;
/dev/mapper/appvg-apilogs_lv                        ext3               20G        173M         19G          1%    /apilogs&lt;BR /&gt;
/dev/mapper/appvg-Introscope_lv                     ext3              3.0G         69M        2.8G          3%    /Introscope&lt;BR /&gt;
/dev/mapper/rootvg-venafi_lv                        ext4              976M        1.3M        924M          1%    /venafi&lt;BR /&gt;
/dev/mapper/appvg-opt_apigee_lv                     ext4              197G        8.9G        178G          5%    /opt/apigee&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:00:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-multivalue-of-field-can-be-extracted-in-the-below-mentioned/m-p/486156#M136025</guid>
      <dc:creator>Rakesh_597</dc:creator>
      <dc:date>2020-09-30T03:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: How multivalue of field can be extracted in the below mentioned event , all the events are in the same format, any solution/query ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-multivalue-of-field-can-be-extracted-in-the-below-mentioned/m-p/486157#M136026</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;| makeresults
| eval _raw="Filesystem,Type,Size,Used,Avail,UsePct,MountedOn
/dev/mapper/rootvg-rootlv,ext3,6.0G,4.3G,1.4G,77%,/
/dev/sda1,ext3,194M,78M,107M,43%,/boot
/dev/mapper/rootvg-home_lv,ext3,2.0G,528M,1.4G,28%,/local_home
/dev/mapper/rootvg-opt_lv,ext3,6.0G,1.2G,4.5G,21%,/opt
/dev/mapper/rootvg-tmp_lv,ext3,2.0G,230M,1.7G,13%,/tmp
/dev/mapper/rootvg-usr_lv,ext3,2.0G,116M,1.8G,7%,/usr/local
/dev/mapper/rootvg-var_lv,ext3,4.0G,1.4G,2.4G,37%,/var
/dev/mapper/rootvg-history_lv,ext3,2.0G,68M,1.9G,4%,/history_logs
/dev/mapper/rootvg-itm_lv,ext3,3.0G,608M,2.3G,22%,/opt/IBM/ITM
/dev/mapper/appvg-apps_lv,ext3,32G,177M,30G,1%,/apps
/dev/mapper/appvg-usr_apigee_lv,ext3,197G,485M,187G,1%,/usr/apigee
/dev/mapper/appvg-apilogs_lv,ext3,20G,173M,19G,1%,/apilogs
/dev/mapper/appvg-Introscope_lv,ext3,3.0G,69M,2.8G,3%,/Introscope
/dev/mapper/rootvg-venafi_lv,ext4,976M,1.3M,924M,1%,/venafi
/dev/mapper/appvg-opt_apigee_lv,ext4,197G,8.9G,178G,5%,/opt/apigee"
| multikv forceheader=1
| table Filesystem,Type,Size,Used,Avail,UsePct,MountedOn
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Multiple values?&lt;BR /&gt;
Do you mean you want to summarize by type?&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2019 00:24:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-multivalue-of-field-can-be-extracted-in-the-below-mentioned/m-p/486157#M136026</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2019-11-17T00:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: How multivalue of field can be extracted in the below mentioned event , all the events are in the same format, any solution/query ?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-multivalue-of-field-can-be-extracted-in-the-below-mentioned/m-p/486158#M136027</link>
      <description>&lt;P&gt;That is the whole point of &lt;CODE&gt;multikv&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|makeresults | eval _raw="Filesystem                      Type Size Used Avail UsePct MountedOn
/dev/mapper/rootvg-rootlv       ext3 6.0G 4.3G  1.4G    77% /
/dev/sda1                       ext3 194M  78M  107M    43% /boot
/dev/mapper/rootvg-home_lv      ext3 2.0G 528M  1.4G    28% /local_home
/dev/mapper/rootvg-opt_lv       ext3 6.0G 1.2G  4.5G    21% /opt
/dev/mapper/rootvg-tmp_lv       ext3 2.0G 230M  1.7G    13% /tmp
/dev/mapper/rootvg-usr_lv       ext3 2.0G 116M  1.8G     7% /usr/local
/dev/mapper/rootvg-var_lv       ext3 4.0G 1.4G  2.4G    37% /var
/dev/mapper/rootvg-history_lv   ext3 2.0G  68M  1.9G     4% /history_logs
/dev/mapper/rootvg-itm_lv       ext3 3.0G 608M  2.3G    22% /opt/IBM/ITM
/dev/mapper/appvg-apps_lv       ext3  32G 177M   30G     1% /apps
/dev/mapper/appvg-usr_apigee_lv ext3 197G 485M  187G     1% /usr/apigee
/dev/mapper/appvg-apilogs_lv    ext3  20G 173M   19G     1% /apilogs
/dev/mapper/appvg-Introscope_lv ext3 3.0G  69M  2.8G     3% /Introscope
/dev/mapper/rootvg-venafi_lv    ext4 976M 1.3M  924M     1% /venafi
/dev/mapper/appvg-opt_apigee_lv ext4 197G 8.9G  178G     5% /opt/apigee"
| multikv forceheader=1 copyattrs=t
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sun, 17 Nov 2019 01:30:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-multivalue-of-field-can-be-extracted-in-the-below-mentioned/m-p/486158#M136027</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-17T01:30:34Z</dc:date>
    </item>
  </channel>
</rss>

