Getting Data In

mvcombine ignores specified delimiter

markwymer
Path Finder

My apologies for the duplicated question - I wasn't sure whether I could tag my particular situation re- mvcombine not using the delimiter when specified.

The search I'm using is
* | stats list(Logon_Source_IP) AS IPList | mvcombine delim=" OR " IPList

what I was hoping to get is (example)
192.10.0.4 OR 192.11.4.23 OR 192.15.12.13

what I'm actually getting back is:
192.10.0.4 192.11.4.23 192.15.12.13

i.e. no delimiter

Any ideas? I did notice that, in another post, someone had used
* | stats delim=" OR " list(Logon_Source_IP) AS IPList
but that ignored the delimiter too.

Any ideas?

0 Karma
1 Solution

markwymer
Path Finder

Hi,

Not sure whether this is a bug or a documentation issue - either way I'm unable to raise a support case as, technically, we're still doing a POC on Splunk.

However, after a phone call and a bit more hunting I came across this document..... http://answers.splunk.com/answers/102260/delim-argument-in-stats-function-no-longer-supported.html - and this answer works perfectly.

My search is now:
* | stats delim=" OR " list(Logon_Source_IP) AS IPList | mvcombine IPList
which gives me the results I'd hoped for.

View solution in original post

markwymer
Path Finder

Hi,

Not sure whether this is a bug or a documentation issue - either way I'm unable to raise a support case as, technically, we're still doing a POC on Splunk.

However, after a phone call and a bit more hunting I came across this document..... http://answers.splunk.com/answers/102260/delim-argument-in-stats-function-no-longer-supported.html - and this answer works perfectly.

My search is now:
* | stats delim=" OR " list(Logon_Source_IP) AS IPList | mvcombine IPList
which gives me the results I'd hoped for.

Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...