<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic array in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/array/m-p/515964#M144907</link>
    <description>&lt;P&gt;Hello&lt;BR /&gt;&lt;BR /&gt;I have log like below&lt;BR /&gt;&lt;BR /&gt;FEATURES_USING=[tokenValidatorInfo=false, requestValidationRequired=false, requestPayloadValidationRequired=false, responsePayloadValidationRequired=false, aopUsed=false, tibcoCommunicatorUsed=false, secretsSecured=false]&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I want result should be like below&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tokenValidatorInfo=false&lt;/P&gt;&lt;P&gt;equestValidationRequired=false&lt;BR /&gt;requestPayloadValidationRequired=false&lt;BR /&gt;responsePayloadValidationRequired=false&lt;BR /&gt;aopUsed=false&lt;BR /&gt;tibcoCommunicatorUsed=false&lt;BR /&gt;secretsSecured=false&lt;/P&gt;</description>
    <pubDate>Tue, 25 Aug 2020 08:37:53 GMT</pubDate>
    <dc:creator>vinod0313</dc:creator>
    <dc:date>2020-08-25T08:37:53Z</dc:date>
    <item>
      <title>array</title>
      <link>https://community.splunk.com/t5/Splunk-Search/array/m-p/515964#M144907</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;&lt;BR /&gt;I have log like below&lt;BR /&gt;&lt;BR /&gt;FEATURES_USING=[tokenValidatorInfo=false, requestValidationRequired=false, requestPayloadValidationRequired=false, responsePayloadValidationRequired=false, aopUsed=false, tibcoCommunicatorUsed=false, secretsSecured=false]&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I want result should be like below&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tokenValidatorInfo=false&lt;/P&gt;&lt;P&gt;equestValidationRequired=false&lt;BR /&gt;requestPayloadValidationRequired=false&lt;BR /&gt;responsePayloadValidationRequired=false&lt;BR /&gt;aopUsed=false&lt;BR /&gt;tibcoCommunicatorUsed=false&lt;BR /&gt;secretsSecured=false&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 08:37:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/array/m-p/515964#M144907</guid>
      <dc:creator>vinod0313</dc:creator>
      <dc:date>2020-08-25T08:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: array</title>
      <link>https://community.splunk.com/t5/Splunk-Search/array/m-p/515977#M144912</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225135"&gt;@vinod0313&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is not clear if you have already extracted any fields but assuming not:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval log="FEATURES_USING=[tokenValidatorInfo=false, requestValidationRequired=false, requestPayloadValidationRequired=false, responsePayloadValidationRequired=false, aopUsed=false, tibcoCommunicatorUsed=false, secretsSecured=false]"
| rex field=log "FEATURES_USING=\[(?&amp;lt;feature&amp;gt;.*)\]" 
| makemv delim=", " feature 
| mvexpand feature 
| fields feature&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could extract the part between the [] into a field, then make it multi-value using ", " as your delimiter, then expand the multi-value field into separate rows.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 09:52:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/array/m-p/515977#M144912</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-08-25T09:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: array</title>
      <link>https://community.splunk.com/t5/Splunk-Search/array/m-p/515983#M144914</link>
      <description>&lt;P&gt;it is not working&lt;BR /&gt;&lt;BR /&gt;my log is shown below&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;05789549ec5f environment=AWS-DEV 2020-08-25 09:33:52 [scheduling-1] [INFO ] [{spanId=e055c0a22de08485, traceId=e055c0a22de08485}] [com.deltadental.platform.common.config.AppConfig:refreshCommonServicesFeatures:93] - FEATURES_USING=[TOKEN_VALIDATION=false, REQUETS_VALIDATION=false, REQUEST_PAYLOAD_VALIDATION=false, RESPONSE_PAYLOAD_VALIDATION=false, AOP=false, TIBCO_COMMUNICATOR=false, SECRETS_SECURE=false]&lt;BR /&gt;&lt;BR /&gt;I want result should like below&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;TOKEN_VALIDATION=false&lt;BR /&gt;REQUETS_VALIDATION=false&lt;BR /&gt;REQUEST_PAYLOAD_VALIDATION=false&lt;BR /&gt;-&lt;BR /&gt;-&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 10:30:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/array/m-p/515983#M144914</guid>
      <dc:creator>vinod0313</dc:creator>
      <dc:date>2020-08-25T10:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: array</title>
      <link>https://community.splunk.com/t5/Splunk-Search/array/m-p/515986#M144916</link>
      <description>&lt;P&gt;Always good to have a real example! However, what is not working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval log="05789549ec5f environment=AWS-DEV 2020-08-25 09:33:52 [scheduling-1] [INFO ] [{spanId=e055c0a22de08485, traceId=e055c0a22de08485}] [com.deltadental.platform.common.config.AppConfig:refreshCommonServicesFeatures:93] - FEATURES_USING=[TOKEN_VALIDATION=false, REQUETS_VALIDATION=false, REQUEST_PAYLOAD_VALIDATION=false, RESPONSE_PAYLOAD_VALIDATION=false, AOP=false, TIBCO_COMMUNICATOR=false, SECRETS_SECURE=false]"
| rex field=log "FEATURES_USING=\[(?&amp;lt;feature&amp;gt;.*)\]" 
| makemv delim=", " feature 
| mvexpand feature 
| fields feature&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gives:&lt;/P&gt;&lt;TABLE border="1" width="25%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%" height="24px"&gt;&lt;STRONG&gt;feature&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;TOKEN_VALIDATION=false&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;REQUETS_VALIDATION=false&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;REQUEST_PAYLOAD_VALIDATION=false&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;RESPONSE_PAYLOAD_VALIDATION=false&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;AOP=false&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;TIBCO_COMMUNICATOR=false&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;SECRETS_SECURE=false&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 25 Aug 2020 10:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/array/m-p/515986#M144916</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-08-25T10:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: array</title>
      <link>https://community.splunk.com/t5/Splunk-Search/array/m-p/515990#M144918</link>
      <description>&lt;P&gt;i am getting below events i am not getting actual expected results&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vinod0313_0-1598352870967.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10489iE858DFC54E8D512A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vinod0313_0-1598352870967.png" alt="vinod0313_0-1598352870967.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 10:54:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/array/m-p/515990#M144918</guid>
      <dc:creator>vinod0313</dc:creator>
      <dc:date>2020-08-25T10:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: array</title>
      <link>https://community.splunk.com/t5/Splunk-Search/array/m-p/515992#M144919</link>
      <description>&lt;P&gt;Yes, the events don't change - you need to look at the results - try adding&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| table feature&lt;/LI-CODE&gt;&lt;P&gt;Then look at the statistics tab&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 10:59:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/array/m-p/515992#M144919</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-08-25T10:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: array</title>
      <link>https://community.splunk.com/t5/Splunk-Search/array/m-p/515994#M144920</link>
      <description>&lt;P&gt;I have added it.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vinod0313_0-1598353413527.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10490iBBE77D5454440FCF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vinod0313_0-1598353413527.png" alt="vinod0313_0-1598353413527.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 11:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/array/m-p/515994#M144920</guid>
      <dc:creator>vinod0313</dc:creator>
      <dc:date>2020-08-25T11:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: array</title>
      <link>https://community.splunk.com/t5/Splunk-Search/array/m-p/515995#M144921</link>
      <description>&lt;P&gt;OK you took my solution too literally! The rex has to be applied to your _raw not my made up log field:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex field=_raw "FEATURES_USING=\[(?&amp;lt;feature&amp;gt;.*)\]"&lt;/LI-CODE&gt;&lt;P&gt;Unless you have already extract FEATURES_USING into its own field&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 11:07:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/array/m-p/515995#M144921</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-08-25T11:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: array</title>
      <link>https://community.splunk.com/t5/Splunk-Search/array/m-p/516233#M145042</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_internal | head 1 | fields _raw
| eval _raw="05789549ec5f environment=AWS-DEV 2020-08-25 09:33:52 [scheduling-1] [INFO ] [{spanId=e055c0a22de08485, traceId=e055c0a22de08485}] [com.deltadental.platform.common.config.AppConfig:refreshCommonServicesFeatures:93] - FEATURES_USING=[TOKEN_VALIDATION=false, REQUETS_VALIDATION=false, REQUEST_PAYLOAD_VALIDATION=false, RESPONSE_PAYLOAD_VALIDATION=false, AOP=false, TIBCO_COMMUNICATOR=false, SECRETS_SECURE=false]"

| kv&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;and search with&amp;nbsp;&lt;STRONG&gt;smart mode&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 11:05:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/array/m-p/516233#M145042</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-08-26T11:05:39Z</dc:date>
    </item>
  </channel>
</rss>

