Splunk Enterprise

how to get string values into column values dynamically

shivareddysompa
Explorer

hi,

i have data like below. i want to string into column values then need to join with my query.

System                   effected Region

a:b:c;d;e;f                  India

i need like below.

system                     effected Region

a                               India

b                               India

c                               India

d                               India

e                                India

f                                 India

 

Thanks in advance

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust
| makeresults | eval _raw="System     effected_Region
a:b:c;d;e;f  India" | multikv forceheader=1
`comment("Above just sets up test data")`
| eval System=split(System,":") | mvexpand System 
| eval System=split(System,";") | mvexpand System

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust
| makeresults | eval _raw="System     effected_Region
a:b:c;d;e;f  India" | multikv forceheader=1
`comment("Above just sets up test data")`
| eval System=split(System,":") | mvexpand System 
| eval System=split(System,";") | mvexpand System

 

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...