<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Split a String field to new rows and extract fields from each value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520952#M146756</link>
    <description>&lt;P&gt;It is a "\n" between links in the string.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Sep 2020 02:56:01 GMT</pubDate>
    <dc:creator>kiru2992</dc:creator>
    <dc:date>2020-09-23T02:56:01Z</dc:date>
    <item>
      <title>New rows for each of the Extracted values from a multi-valued field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520897#M146735</link>
      <description>&lt;P&gt;Hello Everyone!&lt;/P&gt;&lt;P&gt;Currently the result of my query is&amp;nbsp; below:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Input:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;id&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;STRONG&gt;URL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;101&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;https://......-28.../../..../..../..../12304&lt;/P&gt;&lt;P data-unlink="true"&gt;102&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;https://......-28.../../..../..../..../34569&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;https://......-02.../../..../..../..../8976&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;https://......-28.../..../..../741256&lt;/P&gt;&lt;P data-unlink="true"&gt;103&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; https://......-06.../..../..../..../5678&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;https://......-04.../../..../..../..../158930&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to have the output as below:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Output:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;id&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;STRONG&gt;&amp;nbsp;URL&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;fieldA&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;STRONG&gt;fieldB&amp;nbsp;&lt;/STRONG&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;101&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;https://......-28.../../..../..../..../12304&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 28&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 12304&lt;/P&gt;&lt;P data-unlink="true"&gt;102&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;https://......-28.../../..../..../..../34569&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 28&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;34569&lt;/P&gt;&lt;P data-unlink="true"&gt;102&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;https://......-02.../../..../..../..../8976&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;02&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;8976&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;102&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;https://......-28.../..../..../741256&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;28&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;741256&lt;/P&gt;&lt;P data-unlink="true"&gt;103&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;https://......-06.../..../..../..../5678&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;06&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;5678&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;103&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;https://......-04.../../..../..../..../158930&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 04&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;158930&lt;/P&gt;&lt;P data-unlink="true"&gt;I have tried with rex and mvcombine , makemv but not able to achieve the result. I am not sure whether I am using them correctly.&lt;/P&gt;&lt;P data-unlink="true"&gt;Can you please help me to get the output?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 17:13:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520897#M146735</guid>
      <dc:creator>kiru2992</dc:creator>
      <dc:date>2020-09-22T17:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: New rows for each of the Extracted values from a multi-valued field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520901#M146737</link>
      <description>&lt;P&gt;Please share your existing query.&lt;/P&gt;&lt;P&gt;For field extractions using &lt;FONT face="courier new,courier"&gt;rex&lt;/FONT&gt;, we need more details about the data from which the data will be extracted.&amp;nbsp; That is to say the "..." may be hiding important characters that may determine how the regex must be written.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 17:29:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520901#M146737</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-22T17:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: New rows for each of the Extracted values from a multi-valued field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520903#M146739</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I am using the below query for rex now:&lt;/P&gt;&lt;P&gt;| rex max_match=0 field=URL"\/(?&amp;lt;fieldB&amp;gt;[^\/]*)(https:|\n|$)"&lt;/P&gt;&lt;P&gt;I hope this helps in modifing it to get fieldA as well.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 17:54:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520903#M146739</guid>
      <dc:creator>kiru2992</dc:creator>
      <dc:date>2020-09-22T17:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: New rows for each of the Extracted values from a multi-valued field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520908#M146741</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... your search
| eval URL=split(URL,"\n")
| mvexpand URL
| rex field=URL "-(?&amp;lt;fieldA&amp;gt;\d{2}).*\/(?&amp;lt;fieldB&amp;gt;\d+$)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 18:33:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520908#M146741</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-22T18:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Split a String field to new rows and extract fields from each value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520951#M146755</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am sorry, the URL field turns out to be a string field where we have multiple links separated by space. I tried the split command with mvexpand and it is not working .&lt;/P&gt;&lt;P&gt;The rex command worked perfectly! If we are able to split the URL to separate links in the same field then I think we can extract the fieldA and fieldB.&lt;/P&gt;&lt;P&gt;Can you please let me how to split the split the string to new rows?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 02:45:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520951#M146755</guid>
      <dc:creator>kiru2992</dc:creator>
      <dc:date>2020-09-23T02:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Split a String field to new rows and extract fields from each value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520952#M146756</link>
      <description>&lt;P&gt;It is a "\n" between links in the string.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 02:56:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520952#M146756</guid>
      <dc:creator>kiru2992</dc:creator>
      <dc:date>2020-09-23T02:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Split a String field to new rows and extract fields from each value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520975#M146760</link>
      <description>&lt;P&gt;Try this to split the URL string into multiple events&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... your search
| makemv tokenizer="(\S+)" URL
| mvexpand URL
| rex field=URL "-(?&amp;lt;fieldA&amp;gt;\d{2}).*\/(?&amp;lt;fieldB&amp;gt;\d+$)"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 23 Sep 2020 06:54:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/520975#M146760</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-23T06:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: Split a String field to new rows and extract fields from each value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/521774#M147051</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The above code works perfectly:) But I have certain rows where URL is "" and with the above code all the rows with URL as "" is removed.&lt;/P&gt;&lt;P&gt;Can you please let me know how extract new fields retaining all the existing rows?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:28:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/521774#M147051</guid>
      <dc:creator>kiru2992</dc:creator>
      <dc:date>2020-09-28T12:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Split a String field to new rows and extract fields from each value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/521781#M147056</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you also please help me to extract 'fieldA' in case the URL field is available in the below format?&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;STRONG&gt;URL&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;fieldA&lt;/STRONG&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;/opt/splunk-monitor/.../..../28-.../......csv&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;28&lt;/P&gt;&lt;P data-unlink="true"&gt;/opt/splunk-monitor/.../..../08-.../......csv&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;08&lt;/P&gt;&lt;P data-unlink="true"&gt;/opt/splunk-monitor/.../..../....-02/......csv&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 02&lt;/P&gt;&lt;P data-unlink="true"&gt;/opt/splunk-monitor/.../..../....-06/......csv&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 06&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:57:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/521781#M147056</guid>
      <dc:creator>kiru2992</dc:creator>
      <dc:date>2020-09-28T12:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Split a String field to new rows and extract fields from each value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/521811#M147072</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex max_match=0 field=URL "\/[^\d]*(-|)(?&amp;lt;fieldA&amp;gt;\d{2}).*\/(.*csv$|(?&amp;lt;fieldB&amp;gt;\d+$))"&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:07:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/521811#M147072</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-28T14:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Split a String field to new rows and extract fields from each value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/521833#M147080</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Thanks a lot.The extraction works very well:) But as I mentioned above, I have certain rows where URL is "" and with the below code all the rows with URL as "" is removed.&lt;/P&gt;&lt;P&gt;Can you please let me know how extract new fields retaining all the existing rows?&lt;/P&gt;&lt;P&gt;Code:&lt;/P&gt;&lt;PRE&gt;... your search
| makemv tokenizer="(\S+)" URL
| mvexpand URL
| rex field=URL "-(?&amp;lt;fieldA&amp;gt;\d{2}).*\/(?&amp;lt;fieldB&amp;gt;\d+$)"&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:59:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/521833#M147080</guid>
      <dc:creator>kiru2992</dc:creator>
      <dc:date>2020-09-28T14:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Split a String field to new rows and extract fields from each value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/521847#M147086</link>
      <description>&lt;P&gt;The problem here is that mvexpand doesn't work with empty fields so the trick is to add a random string to the field (mvappend, mvcombine), then remove it if it is not the only value in the field (mvfilter), then replace it with an empty string after the mvexpand&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... your search
| eval temp="randomstringwithoutwhitespaces"
| eval URL=mvappend(temp,URL)
| mvcombine delim=" " URL
| makemv tokenizer="(\S+)" URL 
| eval URL=if(mvcount(URL)&amp;gt;1,mvfilter(URL!="randomstringwithoutwhitespaces"),URL)
| mvexpand URL
| eval URL=if(URL="randomstringwithoutwhitespaces","",URL)
| rex field=URL "\/[^\d]*(-|)(?&amp;lt;fieldA&amp;gt;\d{2}).*\/(.*csv$|(?&amp;lt;fieldB&amp;gt;\d+$))"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:02:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/521847#M147086</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-28T16:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Split a String field to new rows and extract fields from each value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/522004#M147176</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Thanks a lot:) This worked like magic:)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:13:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-rows-for-each-of-the-Extracted-values-from-a-multi-valued/m-p/522004#M147176</guid>
      <dc:creator>kiru2992</dc:creator>
      <dc:date>2020-09-29T14:13:12Z</dc:date>
    </item>
  </channel>
</rss>

