All Apps and Add-ons

change the delimiter for multivalue fields

dominiquevocat
SplunkTrust
SplunkTrust

Is it possible to change the delimiter (currently , ) to something else?

I have multivalue fields where the content has "," in them.

Perhaps writing the cell multiline text would help?

0 Karma

dominiquevocat
SplunkTrust
SplunkTrust

I meant for the excel export. I need to reproduce it i fear - i might have mixed up two "issues". I get jumbled output tables with multivalue fields containing "," like LDAP DNs etc. The other issue is that i would like to modify the csv export result from scheduled searches etc. Sorry.

0 Karma

araitz
Splunk Employee
Splunk Employee

This is because the FR delimiter is ";"? And you do mean for the Excel Export app, not Splunk's native CSV Export?

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

See this document:

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Createandmaintainsearch-timefieldextrac...

The useful example here is:

[commalist] 
DELIMS = ", " 
FIELDS = field1, field2, field3 

I think this is exactly what you're looking for to solve the question you're asking.

0 Karma

dominiquevocat
SplunkTrust
SplunkTrust

nope
the values are DN from a directory and i just want to not use "," as the delimiter and not parse the values just output them to a multiline textfield.
I am hoping for the developer to chime in 🙂

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...