<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: normalising duplicate multivalue field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/normalising-duplicate-multivalue-field/m-p/81524#M20661</link>
    <description>&lt;P&gt;There really isn't an easy way globally.&lt;/P&gt;

&lt;P&gt;In general, you might look at:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Using app namespaces to control when particular extractions are performed. If some are only needed in certain contexts, then perhaps these contexts could be separated out into their own app to avoid this kind of conflict&lt;/LI&gt;
&lt;LI&gt;Making the regexes more precise and/or combining multiple regexes into a single one that retrieves multiple fields&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Thu, 14 Apr 2011 11:02:00 GMT</pubDate>
    <dc:creator>gkanapathy</dc:creator>
    <dc:date>2011-04-14T11:02:00Z</dc:date>
    <item>
      <title>normalising duplicate multivalue field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/normalising-duplicate-multivalue-field/m-p/81523#M20660</link>
      <description>&lt;P&gt;so i have numerous field extractions in place. unfortunately due to the number of regex's there are some events that match two field extractions. the issue is that i have the same field name defined in both extractions.&lt;/P&gt;

&lt;P&gt;this isn't a problem as splunk is nice enough to create a multivalue field for me automatically. it just so happens that the value of that field is the same for both entries!&lt;/P&gt;

&lt;P&gt;is there a way i can reduce/normalise this so it doesn't show twice? (without reconstructing my regex's)&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2011 08:07:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/normalising-duplicate-multivalue-field/m-p/81523#M20660</guid>
      <dc:creator>ytl</dc:creator>
      <dc:date>2011-04-14T08:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: normalising duplicate multivalue field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/normalising-duplicate-multivalue-field/m-p/81524#M20661</link>
      <description>&lt;P&gt;There really isn't an easy way globally.&lt;/P&gt;

&lt;P&gt;In general, you might look at:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Using app namespaces to control when particular extractions are performed. If some are only needed in certain contexts, then perhaps these contexts could be separated out into their own app to avoid this kind of conflict&lt;/LI&gt;
&lt;LI&gt;Making the regexes more precise and/or combining multiple regexes into a single one that retrieves multiple fields&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 14 Apr 2011 11:02:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/normalising-duplicate-multivalue-field/m-p/81524#M20661</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-04-14T11:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: normalising duplicate multivalue field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/normalising-duplicate-multivalue-field/m-p/81525#M20662</link>
      <description>&lt;P&gt;oh well... back to restructuring my regex's i guess... just a thought, when i do a top on such a field - would it double count? cheers,&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2011 02:21:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/normalising-duplicate-multivalue-field/m-p/81525#M20662</guid>
      <dc:creator>ytl</dc:creator>
      <dc:date>2011-04-15T02:21:41Z</dc:date>
    </item>
  </channel>
</rss>

