My apologies for the duplicated question - I wasn't sure whether I could tag my particular situation re- mvcombine not using the delimiter when specified.
The search I'm using is
* | stats list(LogonSourceIP) AS IPList | mvcombine delim=" OR " IPList
what I was hoping to get is (example)
184.108.40.206 OR 220.127.116.11 OR 18.104.22.168
what I'm actually getting back is:
22.214.171.124 126.96.36.199 188.8.131.52
i.e. no delimiter
Any ideas? I did notice that, in another post, someone had used
* | stats delim=" OR " list(LogonSourceIP) AS IPList
but that ignored the delimiter too.
Not sure whether this is a bug or a documentation issue - either way I'm unable to raise a support case as, technically, we're still doing a POC on Splunk.
However, after a phone call and a bit more hunting I came across this document..... http://answers.splunk.com/answers/102260/delim-argument-in-stats-function-no-longer-supported.html - and this answer works perfectly.
My search is now:
* | stats delim=" OR " list(LogonSourceIP) AS IPList | mvcombine IPList
which gives me the results I'd hoped for.
View solution in original post