Getting Data In

mvcombine ignores specified delimiter

markwymer
Path Finder

My apologies for the duplicated question - I wasn't sure whether I could tag my particular situation re- mvcombine not using the delimiter when specified.

The search I'm using is
* | stats list(Logon_Source_IP) AS IPList | mvcombine delim=" OR " IPList

what I was hoping to get is (example)
192.10.0.4 OR 192.11.4.23 OR 192.15.12.13

what I'm actually getting back is:
192.10.0.4 192.11.4.23 192.15.12.13

i.e. no delimiter

Any ideas? I did notice that, in another post, someone had used
* | stats delim=" OR " list(Logon_Source_IP) AS IPList
but that ignored the delimiter too.

Any ideas?

0 Karma
1 Solution

markwymer
Path Finder

Hi,

Not sure whether this is a bug or a documentation issue - either way I'm unable to raise a support case as, technically, we're still doing a POC on Splunk.

However, after a phone call and a bit more hunting I came across this document..... http://answers.splunk.com/answers/102260/delim-argument-in-stats-function-no-longer-supported.html - and this answer works perfectly.

My search is now:
* | stats delim=" OR " list(Logon_Source_IP) AS IPList | mvcombine IPList
which gives me the results I'd hoped for.

View solution in original post

markwymer
Path Finder

Hi,

Not sure whether this is a bug or a documentation issue - either way I'm unable to raise a support case as, technically, we're still doing a POC on Splunk.

However, after a phone call and a bit more hunting I came across this document..... http://answers.splunk.com/answers/102260/delim-argument-in-stats-function-no-longer-supported.html - and this answer works perfectly.

My search is now:
* | stats delim=" OR " list(Logon_Source_IP) AS IPList | mvcombine IPList
which gives me the results I'd hoped for.

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...