<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Convert Multivalue field into Number in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520826#M146723</link>
    <description>&lt;P&gt;add below search to your search&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval x_axis=split(x_axis,","),y_axis=split(y_axis,",")
| eval combine=mvzip(x_axis,y_axis)
| fields - x_axis,y_axis
| mvexpand combine
| eval x_axis=mvindex(split(combine,","),0),y_axis=mvindex(split(combine,","),1)
| fields - combine
| table x_axis y_axis&lt;/LI-CODE&gt;&lt;P&gt;below will create sample events as well and show your results:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval x_axis="-1.292015,-1.282425,-1.27523,-1.26725,-1.258461,-1.248871",y_axis="4.9024,5.129161,5.200173,5.327875,5.909696,6.406182"
| eval x_axis=split(x_axis,","),y_axis=split(y_axis,",")
| eval combine=mvzip(x_axis,y_axis)
| fields - x_axis,y_axis
| mvexpand combine
| eval x_axis=mvindex(split(combine,","),0),y_axis=mvindex(split(combine,","),1)
| fields - combine
| table x_axis y_axis&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Sep 2020 12:16:49 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2020-09-22T12:16:49Z</dc:date>
    <item>
      <title>Convert Multivalue field into Number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520807#M146714</link>
      <description>&lt;P&gt;Hey there,&lt;/P&gt;&lt;P&gt;I have extracted chart data from the raw field into multivalue fields. But I can't chart the data since splunk doesn't recoginse the the fields as numbers.&lt;/P&gt;&lt;TABLE border="1" width="102.49318848743764%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;x_axis&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="multivalue-subcell"&gt;y_axis&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="49.87012987012987%"&gt;&lt;DIV class="multivalue-subcell"&gt;-1.292015&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;-1.282425&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;-1.27523&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;-1.26725&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;-1.258461&lt;/DIV&gt;&lt;DIV class="multivalue-subcell highlighted"&gt;-1.248871&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="49.87012987012987%"&gt;&lt;DIV class="multivalue-subcell"&gt;4.9024&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;5.129161&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;5.200173&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;5.327875&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;5.909696&lt;/DIV&gt;&lt;DIV class="multivalue-subcell"&gt;6.406182&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried to convert it using:&lt;/P&gt;&lt;PRE&gt;|eval x_axis2=tonumber(trim(x_axis))&lt;/PRE&gt;&lt;P&gt;or:&lt;/P&gt;&lt;PRE&gt;| Convert num(x_axis)&lt;/PRE&gt;&lt;P&gt;but both didn't work. Could anybody help me out here?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 11:48:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520807#M146714</guid>
      <dc:creator>matthaeus</dc:creator>
      <dc:date>2020-09-22T11:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Multivalue field into Number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520816#M146716</link>
      <description>&lt;P&gt;Try this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval x_axis=mvmap(x_axis, tonumber(x_axis))
| eval y_axis=mvmap(y_axis, tonumber(y_axis))&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 22 Sep 2020 11:58:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520816#M146716</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-22T11:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Multivalue field into Number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520817#M146717</link>
      <description>&lt;P&gt;Hmm.. it just gives me the error message: Error in 'eval' command: The 'mvmap' function is unsupported or undefined.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 12:00:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520817#M146717</guid>
      <dc:creator>matthaeus</dc:creator>
      <dc:date>2020-09-22T12:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Multivalue field into Number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520818#M146718</link>
      <description>&lt;P&gt;Which version of splunk are you running?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 12:02:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520818#M146718</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-22T12:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Multivalue field into Number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520820#M146719</link>
      <description>&lt;P&gt;Can you extract the x-axis and y-axis values into separate event rather than multi-value fields? if not, you could mvzip them together with a suitable delimiter, then mvexpand to get separate events. Then split the field and re-evaluate x-axis and y-axis. Then you will have something to chart.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 12:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520820#M146719</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-22T12:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Multivalue field into Number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520821#M146720</link>
      <description>&lt;P&gt;Splunk Enterprise&lt;/P&gt;&lt;P&gt;Version:7.2.10&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 12:05:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520821#M146720</guid>
      <dc:creator>matthaeus</dc:creator>
      <dc:date>2020-09-22T12:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Multivalue field into Number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520823#M146721</link>
      <description>&lt;P&gt;How exactly do you mean?&lt;/P&gt;&lt;P&gt;So I have extracted it using:&lt;/P&gt;&lt;P&gt;| rex field=_raw max_match=0 (?&amp;lt;x_axis&amp;gt;.\d.\d+);(?&amp;lt;y_axis&amp;gt;\d+.\d+)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry, I'm quite new to splunk &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 12:07:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520823#M146721</guid>
      <dc:creator>matthaeus</dc:creator>
      <dc:date>2020-09-22T12:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Multivalue field into Number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520825#M146722</link>
      <description>&lt;P class="lia-align-justify"&gt;So I think I actually don't have a multivalue field, splunk just recognises it as one since it sees the "." as a delimiter rather than a comma.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 12:13:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520825#M146722</guid>
      <dc:creator>matthaeus</dc:creator>
      <dc:date>2020-09-22T12:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Multivalue field into Number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520826#M146723</link>
      <description>&lt;P&gt;add below search to your search&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval x_axis=split(x_axis,","),y_axis=split(y_axis,",")
| eval combine=mvzip(x_axis,y_axis)
| fields - x_axis,y_axis
| mvexpand combine
| eval x_axis=mvindex(split(combine,","),0),y_axis=mvindex(split(combine,","),1)
| fields - combine
| table x_axis y_axis&lt;/LI-CODE&gt;&lt;P&gt;below will create sample events as well and show your results:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval x_axis="-1.292015,-1.282425,-1.27523,-1.26725,-1.258461,-1.248871",y_axis="4.9024,5.129161,5.200173,5.327875,5.909696,6.406182"
| eval x_axis=split(x_axis,","),y_axis=split(y_axis,",")
| eval combine=mvzip(x_axis,y_axis)
| fields - x_axis,y_axis
| mvexpand combine
| eval x_axis=mvindex(split(combine,","),0),y_axis=mvindex(split(combine,","),1)
| fields - combine
| table x_axis y_axis&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 12:16:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520826#M146723</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-22T12:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Convert Multivalue field into Number</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520831#M146724</link>
      <description>&lt;P&gt;Thanks so much for your suggested solution, but for some reason I already don't have any results after the first line:&lt;/P&gt;&lt;PRE&gt;| eval x_axis=split(x_axis,","),y_axis=split(y_axis,",")&lt;/PRE&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 12:27:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Convert-Multivalue-field-into-Number/m-p/520831#M146724</guid>
      <dc:creator>matthaeus</dc:creator>
      <dc:date>2020-09-22T12:27:14Z</dc:date>
    </item>
  </channel>
</rss>

