<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues of Defining Fields from Split Row within Extracted Events in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Issues-of-Defining-Fields-from-Split-Row-within-Extracted-Events/m-p/566252#M197348</link>
    <description>&lt;P&gt;If there is no trailing pipe you could index from the end&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval datafiles=split(mvindex(SQLField,mvcount(SQLField)-2),"|")
| eval ID_DataFile=mvindex(datafiles,mvcount(datafiles)-2)
| eval ID_DataTempFile=mvindex(datafiles,mvcount(datafiles)-1)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Sep 2021 07:14:00 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-09-08T07:14:00Z</dc:date>
    <item>
      <title>Issues of Defining Fields from Split Row within Extracted Events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issues-of-Defining-Fields-from-Split-Row-within-Extracted-Events/m-p/566213#M197329</link>
      <description>&lt;P class="x_MsoNormal"&gt;Hello&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;I have some issues with Defining Fields from Splitted&amp;nbsp; Raw Data within an Event. Sample Events, Code used to split Raw Event, Output of Splitted Data, and My Issues are given below :&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;STRONG&gt;Raw Events:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;A href="mailto:D7CNB_L_0__20210630-235749_5827.html@%5e@%5e2021/06/30@%5e@%5e23:57:49@%5e@%5eD7CNB@%5e@%5eselect" target="_blank" rel="noopener"&gt;DAS7CNB_L_0__20210630-23574912_5827.html@^@^2021/06/30@^@^23:57:49@^@^DAS7CNB@^@^select&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;"tin","payer_tin","min"(case when "state" in( 'AA','AE','AP','AS','FM','GU','MH','MP','PR','PW','VI' ) then 1 else 0 end) as "f1065k1nonus","max"(case when "state" in( 'WA','OR','CA','AK','HI','MT','ID','WY','NV','UT','CO','AZ','NM' ) then 1 when "state" in( 'ND','MN','SD','IA','NE','KS','MO','WI','IL','IN','MI','OH' ) then 2 when "state" in( 'NY','PA','NJ','NH','VT','ME','MA','RI','CT' ) then 3 when "state" in( 'TX','OK','AR','LA','KY','TN','MS','AL','WV','DE','MD','VA','NC','DC','SC','GA','FL' ) then 4 when "state" in( 'AA','AE','AP','AS','FM','GU','MH','MP','PR','PW','VI' ) then 5 else 0 end) as "f1065k1maxdistoff","max"("interest") as "interest_f1065_k1","max"("guarpaymt") as "guarpaymt_f1065_k1","max"("ord_inc") as "ord_inc_f1065_k1","max"("othrental") as "othrental_f1065_k1","max"("realestate") as "realestate_f1065_k1","max"("royalties") as "royalties_f1065_k1","max"("section179") as "section179_f1065_k1" into #TEMP9A from "irmf_f1065_k1" where "tax_yr" = 2016 and "tin" &amp;gt; 0 and "tin_typ" in( 0,1,2,3 ) group by "tin","payer_tin"@^@^|DAS7CNB.#TEMP9A|cdwsa.IRMF_F1065_K1@^@^&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;STRONG&gt;My SQL Command:&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;eval SQLField=split(_raw,"@^@^")| table SQLField&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;STRONG&gt;Output of Splitted Data:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;DAS7CNB_L_0__20210630-23574912_5827.html&lt;/P&gt;&lt;P&gt;2021/06/30&lt;/P&gt;&lt;P&gt;23:57:49&lt;/P&gt;&lt;P&gt;DAS7CNB&lt;/P&gt;&lt;P&gt;select "a"."basetin","w2nonus","w2maxdistoff","ssanonus","ssamaxdistoff","f1099rnonus","f1099rmaxdistoff","f1099miscnonus","f1099miscmaxdistoff","f1099gnonus","f1099gmaxdistoff","f1099intnonus","f1099intmaxdistoff","f1099oidnonus","f1099oidmaxdistoff","f1041k1nonus","f1041k1maxdistoff","f1065k1nonus","f1065k1maxdistoff","wages_w2","allocated_tips_w2","medicare_wages_w2","taxable_fica_tips_w2","WITHHLDG_w2","pens_annties_f1099_ssa_rrb","withhldg_f1099_ssa_rrb","gross_distrib_f1099r","taxable_amt_f1099r","WITHHLDG_f1099r","non_emp_compensation_f1099misc","othincome_f1099misc","rents_f1099misc","royalties_f1099misc","crop_insurance_f1099misc","WITHHLDG_f1099misc","taxbl_grant_f1099g","UNEMP_COMP_f1099g","prior_refnd_f1099g","agr_subsds_f1099g","atta_pymnt_f1099g","WITHHLDG_f1099g","interest_f1099int","savings_bonds_f1099int","WITHHLDG_f1099int","interest_f1099oid","withhldg_f1099oid","interest_f1041_k1","bus_inc_f1041_k1","net_rental_f1041_k1","oth_prtflo_f1041_k1","oth_rental_f1041_k1","interest_f1065_k1","guarpaymt_f1065_k1","ord_inc_f1065_k1","othrental_f1065_k1","realestate_f1065_k1","royalties_f1065_k1","section179_f1065_k1" into #TEMP9 from(select "basetin","w2nonus","w2maxdistoff","ssanonus","ssamaxdistoff","f1099rnonus","f1099rmaxdistoff","f1099miscnonus","f1099miscmaxdistoff","f1099gnonus","f1099gmaxdistoff","f1099intnonus","f1099intmaxdistoff","f1099oidnonus","f1099oidmaxdistoff","f1041k1nonus","f1041k1maxdistoff","wages_w2","allocated_tips_w2","medicare_wages_w2","taxable_fica_tips_w2","WITHHLDG_w2","pens_annties_f1099_ssa_rrb","withhldg_f1099_ssa_rrb","gross_distrib_f1099r","taxable_amt_f1099r","WITHHLDG_f1099r","non_emp_compensation_f1099misc","othincome_f1099misc","rents_f1099misc","royalties_f1099misc","crop_insurance_f1099misc","WITHHLDG_f1099misc","taxbl_grant_f1099g","UNEMP_COMP_f1099g","prior_refnd_f1099g","agr_subsds_f1099g","atta_pymnt_f1099g","WITHHLDG_f1099g","interest_f1099int","savings_bonds_f1099int","WITHHLDG_f1099int","interest_f1099oid","withhldg_f1099oid","interest_f1041_k1","bus_inc_f1041_k1","net_rental_f1041_k1","oth_prtflo_f1041_k1","oth_rental_f1041_k1" from #TEMP8) as "A" left outer join(select "tin","min"(case when "f1065k1nonus" = 1 then 1 else 0 end) as "f1065k1nonus","max"(case when "f1065k1maxdistoff" = 1 then 1 when "f1065k1maxdistoff" = 2 then 2 when "f1065k1maxdistoff" = 3 then 3 when "f1065k1maxdistoff" = 4 then 4 when "f1065k1maxdistoff" = 5 then 5 else 0 end) as "f1065k1maxdistoff","sum"("interest_f1065_k1") as "interest_f1065_k1","sum"("guarpaymt_f1065_k1") as "guarpaymt_f1065_k1","sum"("ord_inc_f1065_k1") as "ord_inc_f1065_k1","sum"("othrental_f1065_k1") as "othrental_f1065_k1","sum"("realestate_f1065_k1") as "realestate_f1065_k1","sum"("royalties_f1065_k1") as "royalties_f1065_k1","sum"("section179_f1065_k1") as "section179_f1065_k1" from #TEMP9a group by "tin") as "B" on "a"."basetin" = "b"."tin" DAS7CNB.#TEMP9&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DAS7CNB.#TEMP9A|cdsawsa.IRMF_F1065_K1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Issues:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;It splitted as expected.&lt;/P&gt;&lt;P&gt;But, I have some issues with defining&amp;nbsp; &lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;text&amp;nbsp; (please see the text in Bold&amp;nbsp; right above &lt;STRONG&gt;My Issues:&lt;/STRONG&gt;)&amp;nbsp; values&amp;nbsp;&lt;STRONG&gt;DAS7CNB.#TEMP9A&lt;/STRONG&gt;&amp;nbsp; as &lt;STRONG&gt;ID_DataFile&lt;/STRONG&gt; and &lt;STRONG&gt;cdsawsa.IRMF_F1065_K1 &lt;/STRONG&gt;as &lt;STRONG&gt;ID_DataTempFile&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thank you.....any help will be highly appreciated.&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 20:41:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issues-of-Defining-Fields-from-Split-Row-within-Extracted-Events/m-p/566213#M197329</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-09-07T20:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Issues of Defining Fields from Split Row within Extracted Events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issues-of-Defining-Fields-from-Split-Row-within-Extracted-Events/m-p/566225#M197336</link>
      <description>&lt;LI-CODE lang="markup"&gt;| eval datafiles=split(mvindex(SQLField,mvcount(SQLField)-2),"|")
| eval ID_DataFile=mvindex(datafiles,1)
| eval ID_DataTempFile=mvindex(datafiles,2)&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 07 Sep 2021 22:35:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issues-of-Defining-Fields-from-Split-Row-within-Extracted-Events/m-p/566225#M197336</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-09-07T22:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: Issues of Defining Fields from Split Row within Extracted Events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issues-of-Defining-Fields-from-Split-Row-within-Extracted-Events/m-p/566230#M197339</link>
      <description>&lt;P&gt;Thank you so much, appreciated your support.&lt;/P&gt;&lt;P&gt;It's working as expected when I have 2 Pipes "|" (as I mentioned)...but, some cases I found data is with one 1 Pipe "|"&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For Example ......payer_tin"@^@^&lt;STRONG&gt;DAS7CNB.#TEMP9A&lt;/STRONG&gt;|&lt;STRONG&gt;cdwsa.IRMF_F1065_K1&lt;/STRONG&gt;@^@^ ....in that case First Value for I&lt;STRONG&gt;D_DataFile&lt;/STRONG&gt;&amp;nbsp; Field is missing.... Is there anything we can do so that I can have both values in both conditions....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;like&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;payer_tin"@^@^|&lt;STRONG&gt;DAS7CNB.#TEMP9A&lt;/STRONG&gt;|&lt;STRONG&gt;cdwsa.IRMF_F1065_K1&lt;/STRONG&gt;@^@^ (with 2 Pipes) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;AND&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;payer_tin"@^@^&lt;STRONG&gt;DAS7CNB.#TEMP9A&lt;/STRONG&gt;|&lt;STRONG&gt;cdwsa.IRMF_F1065_K1&lt;/STRONG&gt;@^@^ (with 1 Pipe)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you so much again.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 00:56:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issues-of-Defining-Fields-from-Split-Row-within-Extracted-Events/m-p/566230#M197339</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-09-08T00:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Issues of Defining Fields from Split Row within Extracted Events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issues-of-Defining-Fields-from-Split-Row-within-Extracted-Events/m-p/566252#M197348</link>
      <description>&lt;P&gt;If there is no trailing pipe you could index from the end&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval datafiles=split(mvindex(SQLField,mvcount(SQLField)-2),"|")
| eval ID_DataFile=mvindex(datafiles,mvcount(datafiles)-2)
| eval ID_DataTempFile=mvindex(datafiles,mvcount(datafiles)-1)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 07:14:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issues-of-Defining-Fields-from-Split-Row-within-Extracted-Events/m-p/566252#M197348</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-09-08T07:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: Issues of Defining Fields from Split Row within Extracted Events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Issues-of-Defining-Fields-from-Split-Row-within-Extracted-Events/m-p/566309#M197364</link>
      <description>&lt;P&gt;Yes, it's working as expected.&amp;nbsp;Thank you so much, appreciated you support.&lt;/P&gt;&lt;P&gt;Are there any ways I can include these codes into&amp;nbsp; &lt;STRONG&gt;Extraction/Transformation&lt;/STRONG&gt; (please see screenshot below) option and extract as&amp;nbsp; fields from the &lt;STRONG&gt;Add New&lt;/STRONG&gt; Field Under &lt;STRONG&gt;Field Extractions&lt;/STRONG&gt;.&amp;nbsp; Thank you so much again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="malekmo_1-1631109206289.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15909iBCDBB49C1EF12B54/image-size/medium?v=v2&amp;amp;px=400" role="button" title="malekmo_1-1631109206289.png" alt="malekmo_1-1631109206289.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 13:54:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Issues-of-Defining-Fields-from-Split-Row-within-Extracted-Events/m-p/566309#M197364</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-09-08T13:54:34Z</dc:date>
    </item>
  </channel>
</rss>

