<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: multi-value field display in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170080#M48669</link>
    <description>&lt;P&gt;Nope, no go. Here's the result set:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/results_1.jpg" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;I also notice that there is an error that pops up when I use mvexpand. Take a look:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/error_0.jpg" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;This is what happens when I remove the "handler" field:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/results_0.jpg" alt="alt text" /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Dec 2013 16:45:15 GMT</pubDate>
    <dc:creator>tmarlette</dc:creator>
    <dc:date>2013-12-06T16:45:15Z</dc:date>
    <item>
      <title>multi-value field display</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170078#M48667</link>
      <description>&lt;P&gt;I have a search i'm attempting, and I'm trying to find a specific event, and eval the difference, then display that value with a few other fields, in daily buckets. I have most of it done, but this is my first experience dealing with multi value fields, and that's where i'm having my issue. &lt;/P&gt;

&lt;P&gt;This is the query:&lt;/P&gt;

&lt;P&gt;sourcetype=mysource1 OR sourcetype=mysource2 host=myhost1 OR host=myhost2 startdaysago=7 "sequence gap" | bucket_time span=1day | eval dif=(feed_sequence2-feed_sequence1) | stats sum(dif) by _time,handler,host&lt;/P&gt;

&lt;P&gt;The "handler" field has multiple values in it per "host" and I'm attempting to get an output that looks something like [_time,host,handler,count] but I would need the "count" to be per "handler" per "host". &lt;/P&gt;

&lt;P&gt;Right now when I run the query, splunk just thinks that there is only one host, and I assume it's because latest event each day is happening on the same host. &lt;/P&gt;

&lt;P&gt;Any suggestions are greatly appreciated!!! &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:26:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170078#M48667</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2020-09-28T15:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: multi-value field display</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170079#M48668</link>
      <description>&lt;P&gt;What if you break your multi-value fields into individual events with 'mvexpand':&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(sourcetype=mysource1 OR sourcetype=mysource2) (host=myhost1 OR host=myhost2) startdaysago=7 "sequence gap" | mvexpand handler | bucket_time span=1day | eval dif=(feed_sequence2-feed_sequence1) | stats sum(dif) by _time,handler,host
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 06 Dec 2013 16:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170079#M48668</guid>
      <dc:creator>jpass</dc:creator>
      <dc:date>2013-12-06T16:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: multi-value field display</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170080#M48669</link>
      <description>&lt;P&gt;Nope, no go. Here's the result set:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/results_1.jpg" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;I also notice that there is an error that pops up when I use mvexpand. Take a look:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/error_0.jpg" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;This is what happens when I remove the "handler" field:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://answers.splunk.com//storage/results_0.jpg" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2013 16:45:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170080#M48669</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2013-12-06T16:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: multi-value field display</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170081#M48670</link>
      <description>&lt;P&gt;Hmmm. Did you copy and paste my search? I misspelled 'handler' as 'hander'. I corrected it.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2013 16:49:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170081#M48670</guid>
      <dc:creator>jpass</dc:creator>
      <dc:date>2013-12-06T16:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: multi-value field display</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170082#M48671</link>
      <description>&lt;P&gt;ah i see your error does ineed reference handler not hander.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2013 16:50:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170082#M48671</guid>
      <dc:creator>jpass</dc:creator>
      <dc:date>2013-12-06T16:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: multi-value field display</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170083#M48672</link>
      <description>&lt;P&gt;I didn't copy and paste, but great question!!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2013 17:32:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170083#M48672</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2013-12-06T17:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: multi-value field display</title>
      <link>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170084#M48673</link>
      <description>&lt;P&gt;I have essentially the same problem.  In my case, a "scenario" has multiple "slots", slots have multiple "widgets", and widgets have multiple "assets".  I'm trying count the asset ID's per widget / scenario pair.  (slots are not relevant in this query)  &lt;/P&gt;

&lt;P&gt;An input would look like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;
{ 
   \"scenario\": \"webv1\",   
   \"slots\": [
      {  \"name\" : \"slot1\",
         \"widgets\": [  
            {  \"type\": \"A\",
               \"assets\": [ { \"id\": \"d1\" }, 
                                 {  \"id\": \"d2\" } ]  } 
         ]
      },
      {   \"name\" : \"slot2\",
          \"widgets\": [  
           {  \"type\": \"B\",
              \"assets\": [ {  \"id\": \"d3\"} ] }
         ]
      } 
 ]
 }
&lt;/CODE&gt;&lt;/PRE&gt;

The single event appears in a table like this:

&lt;PRE&gt;
&lt;CODE&gt;
scenario   widget   asset-id 
webv1      A            d1
           B            d2
                        d3
 &lt;/CODE&gt;
&lt;/PRE&gt;

&lt;P&gt;I believe I need to expand the single event into one event per asset, and then count that asset-id by the scenario&amp;amp;widget it appears in.  The table for the above event should look like this:&lt;/P&gt;

&lt;PRE&gt;
&lt;CODE&gt;
scenario   widget   asset-id 
webv1      A           d1
webv1      A           d2
webv1      B           d3
&lt;/CODE&gt;
&lt;/PRE&gt;

&lt;P&gt;But mvexpand on the asset-ids gives&lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
webv1    A            d1&lt;BR /&gt;
         B&lt;BR /&gt;
webv1    A            d2&lt;BR /&gt;
         B&lt;BR /&gt;
webv1    A            d3&lt;BR /&gt;
         B&lt;BR /&gt;
&lt;/CODE&gt;&lt;BR /&gt;
&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;The problem is how can you associate A with d1 in one event and d2 in another, and B with d3 in a third?&lt;/P&gt;

&lt;P&gt;Here is a bonus I just picked up for working on problems like this.  You can put the JSON or text for your event directly into your splunk query without having to first retrieve it from somewhere.  This lets you play around with the input very quickly.  Just do this:&lt;/P&gt;

&lt;PRE&gt;
&lt;CODE&gt;
|stats count | fields -count 
| eval response="
{ 
   YOUR JSON GOES HERE, WITH QUOTES ESCAPED
   \"scenario\": \"webv1\",   
   \"slots\": [
      {  \"name\" : \"slot1\",
         \"widgets\": [  
            {  \"type\": \"A\",
               \"assets\": [ { \"id\": \"d1\" }, 
                                 {  \"id\": \"d2\" } ]  } 
         ]
      },
      {   \"name\" : \"slot2\",
          \"widgets\": [  
           {  \"type\": \"B\",
              \"assets\": [ {  \"id\": \"d3\"} ] }
         ]
      } 
 ]
 }

" 
| spath input=response 
| search YOUR QUERY GOES HERE
&lt;/CODE&gt;
&lt;/PRE&gt;</description>
      <pubDate>Fri, 06 Dec 2013 19:46:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/multi-value-field-display/m-p/170084#M48673</guid>
      <dc:creator>prokopowicz</dc:creator>
      <dc:date>2013-12-06T19:46:01Z</dc:date>
    </item>
  </channel>
</rss>

