I have JSON data, which seems to be properly prased. I have a field which holds multiple IPs in a new lined when seen in formatted events and seperated with \n when seen in un-formatted.
Check the below screenshot
I am unable to use mvexpand or split or even i tried to use makemv command but it doesn't work as expected.
Any clue, how to handle this situation, when i do a stats or table i want IPs as multivalued whereas currently it is displayed as just a text with IPs separated with space.
maybe something like this:
... | rex "\"ips\"\:\"(?<all_ips>[^\"]+)"
this will capture all ips as a long string and assign it as a value to the field: "all_ips">
now go to the
... | makemv all_ips delim = "\n" | mvexpand all_ips
hope it helps