<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to separate field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546147#M154801</link>
    <description>&lt;P&gt;Hi, guys. I have a big trouble here.&amp;nbsp;&lt;BR /&gt;I'm using rex to get ip-adresses.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;|rex max_match=0 "(?P&amp;lt;ip0&amp;gt;((?:[0-9]{1,3}\.){3}[0-9]{1,3}.[0-9]{1,9}))"&lt;/P&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;field1:&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;255.255.255.255/1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;255.255.255.255/2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;255.255.255.255/3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;255.255.255.255/4&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;BR /&gt;How can i do this? Please, help &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I want to get something like this&amp;nbsp; &lt;TABLE border="1" width="64%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="20%" height="40px"&gt;field1:&lt;/TD&gt;&lt;TD width="20%" height="40px"&gt;&lt;P&gt;field2:&lt;/P&gt;&lt;/TD&gt;&lt;TD width="20%" height="40px"&gt;field3:&amp;nbsp;&lt;/TD&gt;&lt;TD width="20%" height="40px"&gt;field4:&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%" height="25px"&gt;255.255.255.255/1&lt;/TD&gt;&lt;TD width="20%" height="25px"&gt;255.255.255.255/2&lt;/TD&gt;&lt;TD width="20%" height="25px"&gt;255.255.255.255/3&lt;/TD&gt;&lt;TD width="20%" height="25px"&gt;255.255.255.255/4&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 31 Mar 2021 07:31:55 GMT</pubDate>
    <dc:creator>Dalador</dc:creator>
    <dc:date>2021-03-31T07:31:55Z</dc:date>
    <item>
      <title>How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546147#M154801</link>
      <description>&lt;P&gt;Hi, guys. I have a big trouble here.&amp;nbsp;&lt;BR /&gt;I'm using rex to get ip-adresses.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;|rex max_match=0 "(?P&amp;lt;ip0&amp;gt;((?:[0-9]{1,3}\.){3}[0-9]{1,3}.[0-9]{1,9}))"&lt;/P&gt;&lt;DIV class="multivalue-subcell"&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;field1:&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;255.255.255.255/1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;255.255.255.255/2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;255.255.255.255/3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="100%" height="25px"&gt;255.255.255.255/4&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;BR /&gt;How can i do this? Please, help &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I want to get something like this&amp;nbsp; &lt;TABLE border="1" width="64%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="20%" height="40px"&gt;field1:&lt;/TD&gt;&lt;TD width="20%" height="40px"&gt;&lt;P&gt;field2:&lt;/P&gt;&lt;/TD&gt;&lt;TD width="20%" height="40px"&gt;field3:&amp;nbsp;&lt;/TD&gt;&lt;TD width="20%" height="40px"&gt;field4:&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%" height="25px"&gt;255.255.255.255/1&lt;/TD&gt;&lt;TD width="20%" height="25px"&gt;255.255.255.255/2&lt;/TD&gt;&lt;TD width="20%" height="25px"&gt;255.255.255.255/3&lt;/TD&gt;&lt;TD width="20%" height="25px"&gt;255.255.255.255/4&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:31:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546147#M154801</guid>
      <dc:creator>Dalador</dc:creator>
      <dc:date>2021-03-31T07:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546153#M154802</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults | eval _raw="field1
255.255.255.255/1
255.255.255.255/2
255.255.255.255/3
255.255.255.255/4"
| multikv forceheader=1
| fields field1
| fields - _time _raw

| streamstats count as row
| eval row="field_".row
| eval {row}=field1
| stats values(field_*) as field*&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:38:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546153#M154802</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-03-31T07:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546154#M154803</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233045"&gt;@Dalador&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Try to add :&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| transpose&lt;/LI-CODE&gt;&lt;P&gt;This would create columns based on your rows.&lt;BR /&gt;&lt;BR /&gt;You will probably have to do some renaming and maybe filter some of the new rows, but it should give you what you are asking for.&lt;BR /&gt;&lt;BR /&gt;Best Regards&lt;BR /&gt;&lt;BR /&gt;Ralph&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:39:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546154#M154803</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2021-03-31T07:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546158#M154806</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;Ralph&lt;BR /&gt;Close enough, but i want to get something like this&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="example.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13554i478BE0BDA8908EFD/image-size/large?v=v2&amp;amp;px=999" role="button" title="example.png" alt="example.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:53:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546158#M154806</guid>
      <dc:creator>Dalador</dc:creator>
      <dc:date>2021-03-31T07:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546161#M154807</link>
      <description>&lt;P&gt;Thanks,&amp;nbsp;&lt;BR /&gt;Unfortunately this is not working for me &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;I want something like this:&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="example.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13555i9C961C910A3CE4B9/image-size/large?v=v2&amp;amp;px=999" role="button" title="example.png" alt="example.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:54:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546161#M154807</guid>
      <dc:creator>Dalador</dc:creator>
      <dc:date>2021-03-31T07:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546162#M154808</link>
      <description>&lt;P&gt;You are probably going to have to give a bit more detail - is ip0 a multi-value field or are these separate events? are there other fields you want to keep? what is it about the suggestions that is not working for you?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:57:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546162#M154808</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-03-31T07:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546166#M154812</link>
      <description>&lt;P&gt;This would give you numbered ip* columns&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| transpose
| rename "row *" as ip*
| fields - column&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;This is a modified version of what&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; suggested, which is more flexible than my simple transpose approach:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rename ip0 as ip
| streamstats count as row
| eval row="ip".row
| eval {row}=ip
| stats values(ip*) as ip*&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;But answering &lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546162/highlight/true#M154808" target="_self"&gt;these questions&lt;/A&gt; would really help to find a suitable solution &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 08:05:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546166#M154812</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2021-03-31T08:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546170#M154813</link>
      <description>&lt;P&gt;ip0 is a multi-value field,&amp;nbsp; Sorry, i'm new to splunk and i try to do my best&amp;nbsp;&lt;BR /&gt;i tried to add your solution to my search string and get empty results &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;I want just this 4 ip adresses in separate columns, and add _time, i think&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 08:24:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546170#M154813</guid>
      <dc:creator>Dalador</dc:creator>
      <dc:date>2021-03-31T08:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546175#M154814</link>
      <description>&lt;P&gt;No worries - we all had to start somewhere!&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults | eval _raw="ip0
255.255.255.255/1
255.255.255.255/2
255.255.255.255/3
255.255.255.255/4"
| multikv forceheader=1
| fields ip0
| fields - _raw
| stats values(ip0) as ip0 by _time


| mvexpand ip0
| streamstats count as row by _time
| eval row="ip".row
| eval {row}=ip0
| fields - ip0
| stats values(ip*) as ip* by _time&lt;/LI-CODE&gt;&lt;P&gt;The part before the blank lines just set up the dummy data as a multi-value field&lt;/P&gt;&lt;P&gt;The mvexpand converts the multi-value field into separate events&lt;/P&gt;&lt;P&gt;Streamstats identifies the instance of the multi-value field the event came from&lt;/P&gt;&lt;P&gt;eval converts the count to a name for the resultant field&lt;/P&gt;&lt;P&gt;eval with {} uses the contents of the field (row) as the name of the resultant field&lt;/P&gt;&lt;P&gt;fields removes the original field&lt;/P&gt;&lt;P&gt;stats gathers the fields back into a row based on the original time of the event&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 08:38:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546175#M154814</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-03-31T08:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546184#M154816</link>
      <description>&lt;P&gt;Yep, this&amp;nbsp;&lt;SPAN&gt;almost looks like i want!&amp;nbsp;&lt;BR /&gt;Thanks!&amp;nbsp;&lt;BR /&gt;But, how to&amp;nbsp;unite this two search? I tried to |eval _raw="ip0" and get no results&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="example1.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13557iDCF5F451A5AC76EE/image-size/large?v=v2&amp;amp;px=999" role="button" title="example1.png" alt="example1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="example2.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13558iD1B1840D3176E035/image-size/large?v=v2&amp;amp;px=999" role="button" title="example2.png" alt="example2.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 09:23:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546184#M154816</guid>
      <dc:creator>Dalador</dc:creator>
      <dc:date>2021-03-31T09:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546185#M154817</link>
      <description>&lt;P&gt;You don't need the makeresults part before the blank lines - these just set up some dummy data the demonstrate the bit after the blank lines&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=cisco ... | rex ....
| mvexpand ip0
| streamstats count as row by _time
| eval row="ip".row
| eval {row}=ip0
| fields - ip0
| stats values(ip*) as ip* by _time&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 31 Mar 2021 09:38:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546185#M154817</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-03-31T09:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546202#M154820</link>
      <description>&lt;P&gt;still doesn't work, return&amp;nbsp; with job error&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 11:59:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546202#M154820</guid>
      <dc:creator>Dalador</dc:creator>
      <dc:date>2021-03-31T11:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546204#M154821</link>
      <description>&lt;P&gt;What is the error? Start with your initial search and keep adding lines one at a time to see where the error gets introduced&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 12:08:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546204#M154821</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-03-31T12:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546207#M154823</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233045"&gt;@Dalador&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If every log contains four ip address you can try below;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?P&amp;lt;ip1&amp;gt;(?:[0-9]{1,3}\.){3}[0-9]{1,3}.[0-9]{1,9}).+(?P&amp;lt;ip2&amp;gt;(?:[0-9]{1,3}\.){3}[0-9]{1,3}.[0-9]{1,9}).+(?P&amp;lt;ip3&amp;gt;(?:[0-9]{1,3}\.){3}[0-9]{1,3}.[0-9]{1,9}).+(?P&amp;lt;ip4&amp;gt;(?:[0-9]{1,3}\.){3}[0-9]{1,3}.[0-9]{1,9})"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 31 Mar 2021 12:24:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546207#M154823</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-03-31T12:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546208#M154824</link>
      <description>&lt;P&gt;yes, exactly what i need!&amp;nbsp;&lt;BR /&gt;Thanks, didn't know that we can use rex like this..&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 12:30:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546208#M154824</guid>
      <dc:creator>Dalador</dc:creator>
      <dc:date>2021-03-31T12:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to separate field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546209#M154825</link>
      <description>&lt;P&gt;Thank you, problem is solved&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 12:32:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-separate-field/m-p/546209#M154825</guid>
      <dc:creator>Dalador</dc:creator>
      <dc:date>2021-03-31T12:32:52Z</dc:date>
    </item>
  </channel>
</rss>

