All Apps and Add-ons

split one field in two column

goyals05
Explorer

Hi,

How can we split Time in two different column.

alt text

Tags (2)
0 Karma
1 Solution

elliotproebstel
Champion

If each row has exactly two values for Time, I'd suggest this:

your base search 
| eval first_time=mvindex(Time, 0), last_time=mvindex(Time, 1)

This will create two new fields, each containing one of the values from the Time field.

View solution in original post

elliotproebstel
Champion

If each row has exactly two values for Time, I'd suggest this:

your base search 
| eval first_time=mvindex(Time, 0), last_time=mvindex(Time, 1)

This will create two new fields, each containing one of the values from the Time field.

Get Updates on the Splunk Community!

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

Splunk New Course Releases for a Changing World

Every day, the world feels like it’s moving faster with new technological breakthroughs, AI innovation, and ...