<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Split Row value in single column to multiple row value? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543335#M153908</link>
    <description>&lt;P&gt;try &lt;STRONG&gt;mvexpand&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Mar 2021 09:38:56 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2021-03-11T09:38:56Z</dc:date>
    <item>
      <title>How to Split Row value in single column to multiple row value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543334#M153907</link>
      <description>&lt;P&gt;I want to split row into multiple row by spliting it under the same column.&lt;/P&gt;&lt;P&gt;Example:-&lt;/P&gt;&lt;P&gt;col1&amp;nbsp; &amp;nbsp; &amp;nbsp;col2&amp;nbsp; &amp;nbsp; &amp;nbsp;col3&amp;nbsp; &amp;nbsp; &amp;nbsp;col4&lt;/P&gt;&lt;P&gt;A,a&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Z,z&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; B,b&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; X,x&lt;/P&gt;&lt;P&gt;P,p&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;C,c&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Y,y&lt;/P&gt;&lt;P&gt;V,v&lt;/P&gt;&lt;P&gt;In the above example A,a P,p V,v is in the same row but I want to have it in differet row under column col1.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 08:54:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543334#M153907</guid>
      <dc:creator>abhishekpatel2</dc:creator>
      <dc:date>2021-03-11T08:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to Split Row value in single column to multiple row value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543335#M153908</link>
      <description>&lt;P&gt;try &lt;STRONG&gt;mvexpand&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 09:38:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543335#M153908</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2021-03-11T09:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to Split Row value in single column to multiple row value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543338#M153909</link>
      <description>&lt;P&gt;It wont works because I have varied number of column and I want to split for all the 50 columns that are coming in my output.&lt;/P&gt;&lt;P&gt;So can anyone help me with this...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 09:53:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543338#M153909</guid>
      <dc:creator>abhishekpatel2</dc:creator>
      <dc:date>2021-03-11T09:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to Split Row value in single column to multiple row value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543339#M153910</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;your search 
| streamstats count as session
| mvexpand col1
| streamstats count as session2 by session
| rename col1 as _col1
| foreach col* [ eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; = if(session2=1,mvindex(split(&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;,","),0),mvindex(split(&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;,","),1)) ]
| fields - session*
| rename _col1 as col1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 10:00:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543339#M153910</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2021-03-11T10:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to Split Row value in single column to multiple row value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543340#M153911</link>
      <description>&lt;P&gt;But in my table the value of columns are not like col1,col2 ,etc it is various Name of security attacks.For example:-&lt;A href="http://10.0.9.17:8000/en-US/app/TA-SafeBreach/search?q=search%20index%3D*%20mitre_tactic%20!%3D%20%22null%22%20%0A%7C%20eval%20mitre_tactic%3Dsplit(mitre_tactic%2C%22%2C%22)%2Cmitre_technique%3Dsplit(mitre_technique%2C%22%2C%22)%20%0A%7C%20stats%20count%20by%20mitre_tactic%2Cmitre_technique%2Cresult%20%0A%7C%20eval%20new%3Dmvzip(result%2Ccount)%20%0A%7C%20stats%20sum(count)%20as%20Total%2Cvalues(new)%20as%20new%20by%20mitre_tactic%2Cmitre_technique%20%0A%7C%20mvexpand%20new%20%0A%7C%20search%20new%3D%22not_blocked*%22%20%0A%7C%20eval%20count%3Dmvindex(split(new%2C%22%2C%22)%2C1)%20%0A%7C%20eval%20percent%3D(count%2FTotal)*100%20%0A%7C%20eval%20abc%3Dmvzip(mitre_technique%2Cpercent)%20%0A%7C%20stats%20values(abc)%20by%20mitre_tactic%20%0A%7C%20transpose%200%20header_field%3Dmitre_tactic%7C%20fields%20-%20column&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=&amp;amp;earliest=0&amp;amp;latest=&amp;amp;display.page.search.tab=statistics&amp;amp;display.general.type=statistics&amp;amp;display.visualizations.charting.chart.stackMode=stacked&amp;amp;display.visualizations.charting.chart.showDataLabels=none&amp;amp;display.visualizations.charting.chart=pie&amp;amp;display.visualizations.type=charting&amp;amp;display.visualizations.custom.type=number_display_viz.number_display_viz&amp;amp;sid=1615452177.1253&amp;amp;display.statistics.sortColumn=(TA0003)%20Persistence&amp;amp;display.statistics.sortDirection=asc#" target="_blank" rel="noopener"&gt;(TA0003) Persistence&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This is one of the name of column.&lt;/P&gt;&lt;P&gt;So can anyone help me with this.......&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 10:03:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543340#M153911</guid>
      <dc:creator>abhishekpatel2</dc:creator>
      <dc:date>2021-03-11T10:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to Split Row value in single column to multiple row value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543452#M153934</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=_internal | head 1 | fields _raw
| eval _raw="{\"squadName\":\"Super hero squad\",\"homeTown\":\"Metro City\",\"formed\":2016,\"secretBase\":\"Super tower\",\"active\":true,\"members\":[{\"name\":\"Molecule Man\",\"age\":29,\"secretIdentity\":\"Dan Jukes\",\"powers\":[\"Radiation resistance\",\"Turning tiny\",\"Radiation blast\"]},{\"name\":\"Madame Uppercut\",\"age\":39,\"secretIdentity\":\"Jane Wilson\",\"powers\":[\"Million tonne punch\",\"Damage resistance\",\"Superhuman reflexes\"]},{\"name\":\"Eternal Flame\",\"age\":1000000,\"secretIdentity\":\"Unknown\",\"powers\":[\"Immortality\",\"Heat Immunity\",\"Inferno\",\"Teleportation\",\"Interdimensional travel\"]}]}"
| spath 
| fields - _*
| rename *{}.* as *_*
| rename *{} as *
| table *
``` this is sample data```
``` from here, the logic ```
| eval tmp="val"
| transpose 0 header_field=tmp
| streamstats window=1 count(val) as count
| eventstats max(count) as count
| appendpipe [ eval column="count", val=count]
| fields - count
| dedup column
| transpose 0 header_field=column
| fields - column
| eval count=mvrange(0,count)
| mvexpand count
| rename count as _count
| foreach * [ eval &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt; = mvindex(&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;,_count)]
| fields - _count&lt;/LI-CODE&gt;&lt;P&gt;It counts fields dynamically, so it could be used anywhere.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 20:29:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543452#M153934</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2021-03-11T20:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to Split Row value in single column to multiple row value?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543724#M154020</link>
      <description>&lt;P&gt;No I don't get the needed output yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Mar 2021 12:08:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Split-Row-value-in-single-column-to-multiple-row-value/m-p/543724#M154020</guid>
      <dc:creator>abhishekpatel2</dc:creator>
      <dc:date>2021-03-14T12:08:40Z</dc:date>
    </item>
  </channel>
</rss>

