Hi guys,
How do I split column by comma and convert the result into multiple rows?
eg.
host ips
A 1.1.1.1,1.1.1.2
B 2.2.2.2,2.2.2.3
need to convert to
host ips
A 1.1.1.1
A 1.1.1.2
B 2.2.2.2
B 2.2.2.3
@Liuzhengchen,
Try,
"your current search to get host,ips" |makemv ips delim=","|mvexpand ips
References :
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Makemv
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Mvexpand
@Liuzhengchen,
Try,
"your current search to get host,ips" |makemv ips delim=","|mvexpand ips
References :
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Makemv
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Mvexpand
It works for me. Thank you so much renjith.