All Apps and Add-ons

change the delimiter for multivalue fields

dominiquevocat
SplunkTrust
SplunkTrust

Is it possible to change the delimiter (currently , ) to something else?

I have multivalue fields where the content has "," in them.

Perhaps writing the cell multiline text would help?

0 Karma

dominiquevocat
SplunkTrust
SplunkTrust

I meant for the excel export. I need to reproduce it i fear - i might have mixed up two "issues". I get jumbled output tables with multivalue fields containing "," like LDAP DNs etc. The other issue is that i would like to modify the csv export result from scheduled searches etc. Sorry.

0 Karma

araitz
Splunk Employee
Splunk Employee

This is because the FR delimiter is ";"? And you do mean for the Excel Export app, not Splunk's native CSV Export?

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

See this document:

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Createandmaintainsearch-timefieldextrac...

The useful example here is:

[commalist] 
DELIMS = ", " 
FIELDS = field1, field2, field3 

I think this is exactly what you're looking for to solve the question you're asking.

0 Karma

dominiquevocat
SplunkTrust
SplunkTrust

nope
the values are DN from a directory and i just want to not use "," as the delimiter and not parse the values just output them to a multiline textfield.
I am hoping for the developer to chime in 🙂

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...