<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Split  2 fields into each rows in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Split-2-fields-into-each-rows/m-p/541642#M153354</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Annna_0-1614493032347.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13110iBAEE4BE552E2F837/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Annna_0-1614493032347.png" alt="Annna_0-1614493032347.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;How to have split, i tired many ways but its coming out.&lt;/P&gt;&lt;P&gt;Output:&lt;/P&gt;&lt;TABLE width="198"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="70"&gt;A&lt;/TD&gt;&lt;TD width="64"&gt;B&lt;/TD&gt;&lt;TD width="64"&gt;C&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;288136957&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;66871812&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;288137548&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;62919303&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;288137548&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;69101805&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;288137548&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;84124302&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;488136313&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;66871812&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;488136313&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;65252707&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;488136313&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;65602005&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;488136313&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;69101805&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
    <pubDate>Sun, 28 Feb 2021 06:25:54 GMT</pubDate>
    <dc:creator>Annna</dc:creator>
    <dc:date>2021-02-28T06:25:54Z</dc:date>
    <item>
      <title>Split  2 fields into each rows</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-2-fields-into-each-rows/m-p/541642#M153354</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Annna_0-1614493032347.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13110iBAEE4BE552E2F837/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Annna_0-1614493032347.png" alt="Annna_0-1614493032347.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;How to have split, i tired many ways but its coming out.&lt;/P&gt;&lt;P&gt;Output:&lt;/P&gt;&lt;TABLE width="198"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="70"&gt;A&lt;/TD&gt;&lt;TD width="64"&gt;B&lt;/TD&gt;&lt;TD width="64"&gt;C&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;288136957&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;66871812&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;288137548&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;62919303&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;288137548&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;69101805&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;288137548&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;84124302&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;488136313&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;66871812&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;488136313&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;65252707&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;488136313&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;65602005&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;488136313&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;69101805&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 06:25:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-2-fields-into-each-rows/m-p/541642#M153354</guid>
      <dc:creator>Annna</dc:creator>
      <dc:date>2021-02-28T06:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: Split  2 fields into each rows</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-2-fields-into-each-rows/m-p/541645#M153357</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/227309"&gt;@Annna&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first you could find a different way to aggregate data using the thats command, so instead to use&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats values(B) AS B values(C) AS C BY A&lt;/LI-CODE&gt;&lt;P&gt;you could use something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats BY A B C&lt;/LI-CODE&gt;&lt;P&gt;If this is non acceptable for you, you have to use the the mvexpand command to denormalize your table.&lt;/P&gt;&lt;P&gt;when you have only one field to denormalize it's easy :&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats values(B) AS B values(C) AS C BY A 
| mvexpand B&lt;/LI-CODE&gt;&lt;P&gt;The problem is when you have two or more fields multivalue (as your case) because the order could be different than the real pair fieldB/fieldC.&lt;/P&gt;&lt;P&gt;So you have to aggregate B and C before stats and then split after:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval temp=B."|".C
| stats values(temp) AS temp BY A 
| mvexpand temp
| rex field=temp "^(?&amp;lt;B&amp;gt;\d+)\|(?&amp;lt;C&amp;gt;\d+)"
| table A B C&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 09:33:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-2-fields-into-each-rows/m-p/541645#M153357</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-28T09:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: Split  2 fields into each rows</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-2-fields-into-each-rows/m-p/541972#M153495</link>
      <description>&lt;P&gt;If the data be like this&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0" width="256" cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64" height="20"&gt;A&lt;/TD&gt;&lt;TD width="64"&gt;B&lt;/TD&gt;&lt;TD width="64"&gt;C&lt;/TD&gt;&lt;TD width="64"&gt;D&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="20"&gt;288813&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;45456&lt;/TD&gt;&lt;TD&gt;car&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="100"&gt;388812&lt;/TD&gt;&lt;TD width="64"&gt;1&lt;BR /&gt;2&lt;BR /&gt;3&lt;BR /&gt;4&lt;/TD&gt;&lt;TD width="64"&gt;&lt;BR /&gt;45456&lt;BR /&gt;12312&lt;BR /&gt;78978&lt;BR /&gt;12454&lt;/TD&gt;&lt;TD width="64"&gt;car&lt;BR /&gt;Rose&lt;BR /&gt;Toy&lt;BR /&gt;Bus&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="60"&gt;484784&lt;/TD&gt;&lt;TD width="64"&gt;1&lt;BR /&gt;2&lt;BR /&gt;3&lt;/TD&gt;&lt;TD width="64"&gt;12312&lt;BR /&gt;78978&lt;BR /&gt;12454&lt;/TD&gt;&lt;TD width="64"&gt;Rose&lt;BR /&gt;Toy&lt;BR /&gt;Bus&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;IN above scenario how it works split for &lt;STRONG&gt;the&lt;/STRONG&gt; rows.&lt;/P&gt;&lt;P&gt;output be like:&lt;/P&gt;&lt;TABLE width="256"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64"&gt;A&lt;/TD&gt;&lt;TD width="64"&gt;B&lt;/TD&gt;&lt;TD width="64"&gt;C&lt;/TD&gt;&lt;TD width="64"&gt;D&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;288813&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;45456&lt;/TD&gt;&lt;TD&gt;car&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;388812&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;45456&lt;/TD&gt;&lt;TD&gt;car&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;388812&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;12312&lt;/TD&gt;&lt;TD&gt;Rose&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;388812&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;78978&lt;/TD&gt;&lt;TD&gt;Toy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;388812&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;12454&lt;/TD&gt;&lt;TD&gt;Bus&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;484784&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;12312&lt;/TD&gt;&lt;TD&gt;Rose&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;484784&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;78978&lt;/TD&gt;&lt;TD&gt;Toy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;484784&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;12454&lt;/TD&gt;&lt;TD&gt;Bus&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 02 Mar 2021 14:22:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-2-fields-into-each-rows/m-p/541972#M153495</guid>
      <dc:creator>Annna</dc:creator>
      <dc:date>2021-03-02T14:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Split  2 fields into each rows</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-2-fields-into-each-rows/m-p/541987#M153499</link>
      <description>&lt;P&gt;It depends on whether you have access to the data before it is put into multi-value fields&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval temp=B."|".C."|".D
| stats values(temp) AS temp BY A 
| mvexpand temp
| rex field=temp "^(?&amp;lt;B&amp;gt;[^\|]+)\|(?&amp;lt;C&amp;gt;[^\|]+)\|(?&amp;lt;D&amp;gt;[^\|]+)"
| table A B C D&lt;/LI-CODE&gt;&lt;P&gt;If you don't, it depends if which version of splunk you are using and whether mvzip is available to you&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval temp=mvzip(mvzip(B, C, "|"),D, "|")
| fields - B C D
| mvexpand temp
| rex field=temp "^(?&amp;lt;B&amp;gt;[^\|]+)\|(?&amp;lt;C&amp;gt;[^\|]+)\|(?&amp;lt;D&amp;gt;[^\|]+)"
| table A B C D&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 14:59:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-2-fields-into-each-rows/m-p/541987#M153499</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-03-02T14:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: Split  2 fields into each rows</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-2-fields-into-each-rows/m-p/541999#M153509</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults 
| eval _raw="
A         B          C                          D
288813    1          45456                      car
388812    1|2|3|4    45456|12312|78978|12454    car|Rose|Toy|Bus
484784    1|2|3      12312|78978|12454          Rose|Toy|Bus" 
| multikv forceheader=1 
| fields - _time _raw linecount 
| eval B=split(B,"|"), C=split(C,"|"), D=split(D,"|") 
| eval E=mvzip(B,mvzip(C,D))&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 02 Mar 2021 15:55:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-2-fields-into-each-rows/m-p/541999#M153509</guid>
      <dc:creator>tread_splunk</dc:creator>
      <dc:date>2021-03-02T15:55:00Z</dc:date>
    </item>
  </channel>
</rss>

