<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problems with adding multi-value field through /var/spool/splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-adding-multi-value-field-through-var-spool-splunk/m-p/747568#M241844</link>
    <description>&lt;P&gt;You will need some compromise one way or another. &amp;nbsp;Any specific reason why &lt;FONT face="andale mono,times"&gt;array_field{}&lt;/FONT&gt; is unacceptable? &amp;nbsp;If anything, you can use field alias to allow use of &lt;FONT face="andale mono,times"&gt;array_field&lt;/FONT&gt;. &amp;nbsp;Alternatively you can use calculated field to alter a key-value entry ("classic"), e.g., comma_delimited_field="1,2", then use split to calculate array_field.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jun 2025 15:17:17 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2025-06-05T15:17:17Z</dc:date>
    <item>
      <title>Problems with adding multi-value field through /var/spool/splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-adding-multi-value-field-through-var-spool-splunk/m-p/747559#M241841</link>
      <description>&lt;P&gt;Hi Fellow Splunkers,&lt;BR /&gt;How can I add multi-value field (array) directly to the index through `/var/spool/splunk`.&lt;BR /&gt;I tried multiple approaches:&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;1. Dict&lt;/STRONG&gt;&lt;BR /&gt;==##~~##~~ 1E8N3D4E6V5E7N2T9 ~~##~~##==&lt;BR /&gt;{ "array_field":["1", "2"], "count": "2", ... }&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;2. Classic&lt;/STRONG&gt;&lt;BR /&gt;==##~~##~~ 1E8N3D4E6V5E7N2T9 ~~##~~##==&lt;BR /&gt;... , array_field=["1", "2"], count="2", ...&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I achieved best results with &lt;STRONG&gt;Dict &lt;/STRONG&gt;approach&lt;STRONG&gt;. &lt;/STRONG&gt;Added field correctly has multiple values, however ... to key ("array_field") splunk adds {}, resulting in incorrect key ("array_field{}")&lt;BR /&gt;&lt;BR /&gt;Do you have any suggestions?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2025 08:04:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-adding-multi-value-field-through-var-spool-splunk/m-p/747559#M241841</guid>
      <dc:creator>orpiczy</dc:creator>
      <dc:date>2025-06-06T08:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with adding multi-value field through /var/spool/splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-adding-multi-value-field-through-var-spool-splunk/m-p/747568#M241844</link>
      <description>&lt;P&gt;You will need some compromise one way or another. &amp;nbsp;Any specific reason why &lt;FONT face="andale mono,times"&gt;array_field{}&lt;/FONT&gt; is unacceptable? &amp;nbsp;If anything, you can use field alias to allow use of &lt;FONT face="andale mono,times"&gt;array_field&lt;/FONT&gt;. &amp;nbsp;Alternatively you can use calculated field to alter a key-value entry ("classic"), e.g., comma_delimited_field="1,2", then use split to calculate array_field.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2025 15:17:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-adding-multi-value-field-through-var-spool-splunk/m-p/747568#M241844</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2025-06-05T15:17:17Z</dc:date>
    </item>
  </channel>
</rss>

