<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can you make data to come in different rows using mvzip? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585111#M203823</link>
    <description>&lt;P&gt;Sorry, It was by mistake while writing this question. The error comes in the mvzip part as expected ")".&lt;/P&gt;</description>
    <pubDate>Tue, 15 Feb 2022 08:27:33 GMT</pubDate>
    <dc:creator>anooshac</dc:creator>
    <dc:date>2022-02-15T08:27:33Z</dc:date>
    <item>
      <title>How can you make data to come in different rows using mvzip?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585066#M203803</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I have a query which gives this kind of table.&lt;/P&gt;
&lt;P&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Date&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Task&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SubGroup&lt;/P&gt;
&lt;P&gt;A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14-02-22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PASS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b2&lt;/P&gt;
&lt;P&gt;The data will come together and which but i want separate rows for all the data. Also there are subgroup for some tasks but with this result it one cannot be able to differentiate between them.&lt;/P&gt;
&lt;P&gt;I have tried using mvzip like this,&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;...............| eval tmp=mvzip(mvzip(Name,Task,","),SubGroup,",")

| mvexpand tmp
| table  Name   Date    Status tmp
|eval Name=mvindex(split(tmp,","),0)|eval  Task=mvindex(split(tmp,","),1)|eval  SubGroup=mvindex(split(tmp,","),2)
|table  Name  Date     Status Task   SubGroup&lt;/LI-CODE&gt;
&lt;P&gt;I am not getting why a error comes in eval command as expected ). I don't know whether it is a small mistake, i have tried alot but not able to solve this.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 16:32:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585066#M203803</guid>
      <dc:creator>anooshac</dc:creator>
      <dc:date>2022-02-15T16:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: make data to come in different rows using mvzip.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585071#M203805</link>
      <description>&lt;P&gt;There doesn't appear to be anything wrong with the eval example you have given. How close is it to the real search?&lt;/P&gt;&lt;P&gt;Btw, I think you may be missing a table (or fields) command at the beginning of the last line, and the table command in the middle is redundant.&lt;/P&gt;&lt;P&gt;Also, it is not clear what you events look like at the beginning .........| - if the "table" is supposed to represent a single event with multivalue fields Group Task and SubGroup, then mvzip will lose some of the data since there are only two values in Group, i.e. these will be zipped with two (of the three) values in Task.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 06:49:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585071#M203805</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-02-15T06:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: How can you make data to come in different rows using mvzip?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585080#M203808</link>
      <description>&lt;P&gt;If Group, Task and SubGroup ar multivalued things, the only reasonable thing to do is mvexpand them&lt;/P&gt;&lt;PRE&gt;&amp;lt;your query&amp;gt;&lt;BR /&gt;| mvexpand Group&lt;BR /&gt;| mvexpand Task&lt;BR /&gt;| mvexpand SubGrou&lt;/PRE&gt;&lt;P&gt;Remember that if you from this single line you'll get 18 resulting lines after such operation.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 07:06:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585080#M203808</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-15T07:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: How can you make data to come in different rows using mvzip?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585091#M203811</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;...&lt;BR /&gt;| Name&amp;nbsp; Date&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status Group Task&amp;nbsp;&amp;nbsp; SubGroup&lt;/BLOCKQUOTE&gt;&lt;P&gt;Is that last line missing a command like table?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| table Name  Date     Status Group Task   SubGroup&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 15 Feb 2022 07:26:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585091#M203811</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-02-15T07:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: How can you make data to come in different rows using mvzip?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585110#M203822</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I tried using mvexpand but it is giving some unwanted results. The group has Tasks and Task further has SubGroup. By using only mvexpand the data&amp;nbsp; will not come as expected.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 08:26:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585110#M203822</guid>
      <dc:creator>anooshac</dc:creator>
      <dc:date>2022-02-15T08:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: How can you make data to come in different rows using mvzip?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585111#M203823</link>
      <description>&lt;P&gt;Sorry, It was by mistake while writing this question. The error comes in the mvzip part as expected ")".&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 08:27:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585111#M203823</guid>
      <dc:creator>anooshac</dc:creator>
      <dc:date>2022-02-15T08:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: make data to come in different rows using mvzip.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585112#M203824</link>
      <description>&lt;P&gt;Hi, i have used table command. It was a mistake while writing the question here.&lt;/P&gt;&lt;P&gt;I want a table that consists of Name, Date, Status, Task,SubGroup.&lt;/P&gt;&lt;P&gt;The Name has Task and the Task further has SubGroup. When i directly put them in to the table all data will get mixed. It is difficult to differentiate which Task the SubGroup belongs to and which Group the Task belongs to. And the error comes in the mvzip command as "&lt;SPAN&gt;Error in 'eval' command: The expression is malformed. Expected ).&lt;/SPAN&gt;" Not getting what went wrong.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 11:04:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585112#M203824</guid>
      <dc:creator>anooshac</dc:creator>
      <dc:date>2022-02-15T11:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: make data to come in different rows using mvzip.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585113#M203825</link>
      <description>&lt;P&gt;Please can you share you full search (preferably in a code block &amp;lt;/&amp;gt;)?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 08:54:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585113#M203825</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-02-15T08:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: make data to come in different rows using mvzip.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585142#M203838</link>
      <description>&lt;P&gt;sure. This is the query which i am using. I am using JSON input.&lt;/P&gt;&lt;P&gt;index= "abc" sourcetype="xyz"&lt;/P&gt;&lt;P&gt;|eval "Date"=strftime(TASK_TIME/1000,"%F %H:%M")&lt;BR /&gt;| rename GROUP_NUM as "Name" GROUP_STATUS as "Status" GROUP_COMPONENTS{}.TASK_NAME as Task GROUP_COMPONENTS{}.SUBTASK{} as "SubGroup"| eval tmp=mvzip(mvzip(Name,Task","),SubGroup,",")&lt;BR /&gt;| mvexpand tmp&lt;BR /&gt;| table "Date" "Status" tmp| eval Name=mvindex(split(tmp,","),0)&lt;BR /&gt;|eval Task=mvindex(split(tmp,","),1)|eval SubGroup=mvindex(split(tmp,","),2)&lt;BR /&gt;| table Name Date Status Task SubGroup&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 10:56:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585142#M203838</guid>
      <dc:creator>anooshac</dc:creator>
      <dc:date>2022-02-15T10:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: make data to come in different rows using mvzip.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585183#M203860</link>
      <description>&lt;P&gt;Your syntax as you have shown looks OK. The field names you have shown look OK too.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 15:09:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585183#M203860</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-02-15T15:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: How can you make data to come in different rows using mvzip?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585184#M203861</link>
      <description>&lt;P&gt;Can there be cases where your data looks like this? Is there a pattern between values of fields Task and SubGroup?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="20%"&gt;Name&lt;/TD&gt;&lt;TD width="20%"&gt;Date&lt;/TD&gt;&lt;TD width="20%"&gt;Status&amp;nbsp;&lt;/TD&gt;&lt;TD width="20%"&gt;Task&lt;/TD&gt;&lt;TD width="20%"&gt;SubGroup&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="20%"&gt;A&lt;/TD&gt;&lt;TD width="20%"&gt;14-02-22&lt;/TD&gt;&lt;TD width="20%"&gt;PASS&lt;/TD&gt;&lt;TD width="20%"&gt;&lt;P&gt;a&lt;/P&gt;&lt;P&gt;b&lt;/P&gt;&lt;/TD&gt;&lt;TD width="20%"&gt;&lt;P&gt;a1&lt;/P&gt;&lt;P&gt;a2&lt;/P&gt;&lt;P&gt;b1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 15 Feb 2022 15:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585184#M203861</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2022-02-15T15:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: How can you make data to come in different rows using mvzip?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585207#M203866</link>
      <description>&lt;P&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Date&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Task&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SubGroup&lt;/P&gt;&lt;P&gt;A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14-02-22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PASS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a1&lt;/P&gt;&lt;P&gt;A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14-02-22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PASS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a2&lt;/P&gt;&lt;P&gt;A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14-02-22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PASS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b1&lt;/P&gt;&lt;P&gt;This is how the results are supposed to come.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;This is the query which i am using. I am using JSON input. There is relation between Task and SubGroup.&lt;/P&gt;&lt;P&gt;index= "abc" sourcetype="xyz"&lt;/P&gt;&lt;P&gt;|eval "Date"=strftime(TASK_TIME/1000,"%F %H:%M")&lt;BR /&gt;| rename GROUP_NUM as "Name" GROUP_STATUS as "Status" GROUP_COMPONENTS{}.TASK_NAME as Task GROUP_COMPONENTS{}.SUBTASK{} as "SubGroup"| eval tmp=mvzip(mvzip(Name,Task","),SubGroup,",")&lt;BR /&gt;| mvexpand tmp&lt;BR /&gt;| table "Date" "Status" tmp| eval Name=mvindex(split(tmp,","),0)&lt;BR /&gt;|eval Task=mvindex(split(tmp,","),1)|eval SubGroup=mvindex(split(tmp,","),2)&lt;BR /&gt;| table Name Date Status Task SubGroup&lt;/P&gt;&lt;P&gt;I am getting a error as "&lt;SPAN&gt;Error in 'eval' command: The expression is malformed. Expected ).&lt;/SPAN&gt;" Don't know what went wrong.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 17:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585207#M203866</guid>
      <dc:creator>anooshac</dc:creator>
      <dc:date>2022-02-15T17:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: How can you make data to come in different rows using mvzip?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585208#M203867</link>
      <description>&lt;P&gt;And how would you decide which of those mvfield values correspond with which ones from another mvfield? I understand that you're creating it from json. Unfortunately, splunk isn't very good at manipulating complex data structures.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 17:08:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585208#M203867</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-15T17:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: make data to come in different rows using mvzip.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585247#M203876</link>
      <description>&lt;P&gt;Yes. This looks ok but I am getting a error as "Error in 'eval' command: The expression is malformed. Expected )."&amp;nbsp; I don't know whether this error is related to mvzip.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 04:18:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585247#M203876</guid>
      <dc:creator>anooshac</dc:creator>
      <dc:date>2022-02-16T04:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: make data to come in different rows using mvzip.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585277#M203894</link>
      <description>&lt;P&gt;There is a typo in the inner mvzip: missing a comma between Task and the joiner ",". &amp;nbsp;The correct search would read&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval "Date"=strftime(TASK_TIME/1000,"%F %H:%M")
| rename GROUP_NUM as "Name" GROUP_STATUS as "Status" GROUP_COMPONENTS{}.TASK_NAME as Task GROUP_COMPONENTS{}.SUBTASK{} as "SubGroup"
| eval tmp=mvzip(mvzip(Name,Task,","),SubGroup,",") ``` pay attention to this ```
| mvexpand tmp
| table "Date" "Status" tmp
| eval Name=mvindex(split(tmp,","),0)
| eval Task=mvindex(split(tmp,","),1)
| eval SubGroup=mvindex(split(tmp,","),2)
| table Name Date Status Task SubGroup&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is how I diagnose the problem:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Spread every pipe (|) into its own line. (This is a good habit in everyday programming, too.)&lt;/LI&gt;&lt;LI&gt;Take away half the eval()s and observe.&lt;/LI&gt;&lt;LI&gt;If error exists, take away another half of remainder, and so on.&lt;/LI&gt;&lt;LI&gt;If the first half did not contain error, take away the first half, and split the second half. &amp;nbsp;And so on.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Really what you are doing is to simply spot the syntax error (or formatting error in this case), not to worry about output.&lt;/P&gt;&lt;P&gt;Eventually I spotted this&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;&lt;FONT face="courier new,courier"&gt;| makeresults&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| eval tmp=mvzip(mvzip(Name,Task","),SubGroup,",")&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;Error in 'eval' command: The expression is malformed. Expected ).&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Wed, 16 Feb 2022 06:42:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585277#M203894</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-02-16T06:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: make data to come in different rows using mvzip.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585311#M203904</link>
      <description>&lt;P&gt;Thank you..&amp;nbsp; i didn't notice the comma! and thanks for the info!&lt;/P&gt;&lt;P&gt;Now i am able to get the table but it has only one row. It should have multiple rows.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 09:42:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585311#M203904</guid>
      <dc:creator>anooshac</dc:creator>
      <dc:date>2022-02-16T09:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: make data to come in different rows using mvzip.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585324#M203912</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Now i am able to get the table but it has only one row. It should have multiple rows.&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Apply the same diagnostic steps. &amp;nbsp;Cut off everything below mvexpand, see if that is giving you multiple rows, i.e., whether that double mvzip (tmp) gives multivalue.&lt;/P&gt;&lt;P&gt;The reason why tmp only has one value is because Name is single value. &amp;nbsp;Zip it to anything results in this value tied to the first value of the other field.&lt;/P&gt;&lt;P&gt;See the following simulation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval Name="A", Task=mvappend("a", "b"), Subgroup=mvappend("a1", "b1", "b2")
``` the above simulates original table ```

| eval tmp=mvzip(mvzip(Name, Task, ","), Subgroup, ",")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Name&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;Subgroup&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;Task&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;TD&gt;tmp&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;a1&lt;/DIV&gt;&lt;DIV class=""&gt;b1&lt;/DIV&gt;&lt;DIV class=""&gt;b2&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;a&lt;/DIV&gt;&lt;DIV class=""&gt;b&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;2022-02-16 03:07:06&lt;/TD&gt;&lt;TD&gt;A,a,a1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 16 Feb 2022 11:11:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585324#M203912</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-02-16T11:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: How can you make data to come in different rows using mvzip?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585327#M203914</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/30057"&gt;@anooshac&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Date&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Task&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SubGroup&lt;/P&gt;&lt;P&gt;A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14-02-22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PASS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a1&lt;/P&gt;&lt;P&gt;A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14-02-22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PASS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a2&lt;/P&gt;&lt;P&gt;A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14-02-22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PASS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b1&lt;/P&gt;&lt;P&gt;This is how the results are supposed to come.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This is not a use case for mvzip; instead, just apply mvexpand and filter spurious rows using known relationship between Task and SubGroup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval Name="A", Task=mvappend("a", "b"), SubGroup=mvappend("a1", "b1", "b2"), Status="Pass"
``` the above simulates original table ```

| mvexpand SubGroup
| mvexpand Task
| where match(SubGroup, Task) ``` THIS IS APPLICATION SPECIFIC KNOWLEDGE. Use your real relationship ```
| table  Name  _time     Status Task   SubGroup ``` use _time for simulation ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Name&lt;/TD&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;TD&gt;Status&lt;/TD&gt;&lt;TD&gt;Task&lt;/TD&gt;&lt;TD&gt;SubGroup&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A&lt;/TD&gt;&lt;TD&gt;2022-02-16 03:29:50&lt;/TD&gt;&lt;TD&gt;Pass&lt;/TD&gt;&lt;TD&gt;a&lt;/TD&gt;&lt;TD&gt;a1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A&lt;/TD&gt;&lt;TD&gt;2022-02-16 03:29:50&lt;/TD&gt;&lt;TD&gt;Pass&lt;/TD&gt;&lt;TD&gt;b&lt;/TD&gt;&lt;TD&gt;b1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A&lt;/TD&gt;&lt;TD&gt;2022-02-16 03:29:50&lt;/TD&gt;&lt;TD&gt;Pass&lt;/TD&gt;&lt;TD&gt;b&lt;/TD&gt;&lt;TD&gt;b2&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 16 Feb 2022 11:34:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585327#M203914</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-02-16T11:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: make data to come in different rows using mvzip.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585328#M203915</link>
      <description>&lt;P&gt;My guess would be that the events you have are structured something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{"GROUP_NUM":"123",
"GROUP_STATUS":"OK",
"GROUP_COMPONENTS":[
{
"TASK_NAME":"t1",
"SUBTASK":[
"a1","a2"]
},
{
"TASK_NAME":"t2",
"SUBTASK":[
"b1","b2"]
}
]
}&lt;/LI-CODE&gt;&lt;P&gt;You may want to consider extracting the GROUP_COMPONENTS collection out and using mvexpand on that before extracting the TASK_NAME and SUBTASK collection&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="{\"GROUP_NUM\":\"123\",
\"GROUP_STATUS\":\"OK\",
\"GROUP_COMPONENTS\":[{
\"TASK_NAME\":\"t1\",
\"SUBTASK\":[\"a1\",\"a2\"]
},
{
\"TASK_NAME\":\"t2\",
\"SUBTASK\":[\"b1\",\"b2\"]
}]
}"
| spath GROUP_NUM
| spath GROUP_STATUS
| spath GROUP_COMPONENTS{} output=Components
| mvexpand Components
| spath input=Components&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 16 Feb 2022 11:37:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-you-make-data-to-come-in-different-rows-using-mvzip/m-p/585328#M203915</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-02-16T11:37:37Z</dc:date>
    </item>
  </channel>
</rss>

