Hi
Can someone help me with the splunk query where i need to display only eapply as the key
...|eval key=mvindex(split(nbamboo_buildkey,"="),1) | table key
it displays all the bamboo_buildkey along with eapply, repository number, etc 
 
		
		
		
		
		
	
			
		
		
			
					
		Will this work?
...|eval key=mvindex(split(nbamboo_buildkey,"="),1) 
| where key="eapply"
| table key 
		
		
		
		
		
	
			
		
		
			
					
		Hi @Nith1,
Can you please give a sample event for nbamboo_buildkey for us to help?
