Splunk Enterprise

how to get string values into column values dynamically

shivareddysompa
Explorer

hi,

i have data like below. i want to string into column values then need to join with my query.

System                   effected Region

a:b:c;d;e;f                  India

i need like below.

system                     effected Region

a                               India

b                               India

c                               India

d                               India

e                                India

f                                 India

 

Thanks in advance

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust
| makeresults | eval _raw="System     effected_Region
a:b:c;d;e;f  India" | multikv forceheader=1
`comment("Above just sets up test data")`
| eval System=split(System,":") | mvexpand System 
| eval System=split(System,";") | mvexpand System

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust
| makeresults | eval _raw="System     effected_Region
a:b:c;d;e;f  India" | multikv forceheader=1
`comment("Above just sets up test data")`
| eval System=split(System,":") | mvexpand System 
| eval System=split(System,";") | mvexpand System

 

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...