Knowledge Management

mkvalue - strange problem

adamguzek
Explorer

Log line:

eventDate="2014-03-24 14:42:00.945" eventType="adam.test" eventDevice="test.client" dstip="44.184.5.99" srcip="44.184.5.99" domain="value6" domain="value9" ver="5" dstport="5" srcport="4" user="value4" proto="value8"

Search:

eventType="adam.test" | eval domain1=mvindex(domain,1)

Result? Everything but no domain1 field.

I am trying to search by second or first "domain" field value eval'ing it into domain1 - no luck.

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The changes needed depend on how you're indexing the data now. Adding 'MV_ADD=true' to your props.conf file may be enough. Providing your current relevant props.conf (and transforms.conf) stanzas will help us help you better.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The changes needed depend on how you're indexing the data now. Adding 'MV_ADD=true' to your props.conf file may be enough. Providing your current relevant props.conf (and transforms.conf) stanzas will help us help you better.

---
If this reply helps you, Karma would be appreciated.

adamguzek
Explorer

MV_ADD=true was the trick...

0 Karma

adamguzek
Explorer

You are right, Splunk indexed only one value for domain field... but why?

Where and how should I configure that source to index data correctly?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Run the following search to see what exactly Splunk has indexed from that log line.

eventType="adam.test" | table *

That should give you a better idea about how to build your query.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...