All Apps and Add-ons

change the delimiter for multivalue fields

dominiquevocat
SplunkTrust
SplunkTrust

Is it possible to change the delimiter (currently , ) to something else?

I have multivalue fields where the content has "," in them.

Perhaps writing the cell multiline text would help?

0 Karma

dominiquevocat
SplunkTrust
SplunkTrust

I meant for the excel export. I need to reproduce it i fear - i might have mixed up two "issues". I get jumbled output tables with multivalue fields containing "," like LDAP DNs etc. The other issue is that i would like to modify the csv export result from scheduled searches etc. Sorry.

0 Karma

araitz
Splunk Employee
Splunk Employee

This is because the FR delimiter is ";"? And you do mean for the Excel Export app, not Splunk's native CSV Export?

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

See this document:

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Createandmaintainsearch-timefieldextrac...

The useful example here is:

[commalist] 
DELIMS = ", " 
FIELDS = field1, field2, field3 

I think this is exactly what you're looking for to solve the question you're asking.

0 Karma

dominiquevocat
SplunkTrust
SplunkTrust

nope
the values are DN from a directory and i just want to not use "," as the delimiter and not parse the values just output them to a multiline textfield.
I am hoping for the developer to chime in 🙂

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise Security 8.0!

Join us on Wednesday, November 20 to learn about Splunk Enterprise Security 8.0!To enhance SOC efficiency, ...

Mastering Threat Hunting

Register to watch Mastering Threat Hunting on Monday, November 18Join us for an insightful talk where we dive ...

Upcoming Community Maintenance: 10/28

Howdy folks, just popping in to let you know that the Splunk Community site will be in read-only mode ...