I am working with a log that can sometimes have the same field in one log entry more than one time, but with multiple values.
100=A 100=B 100=C
As I've seen discussed before, Splunk only seems to pull the first value out whenever the field is repeated. What would be the best way to tell Splunk at searchtime that I want to pull all "100" values from the log and not just the first one?
If you just want to get the values in the same field as a multivalve field, then this type search should work:
| makeresults | eval _raw="100=A 100=B 100=C" | rex field=_raw max_match=10 "100=(?P<field100>\w+)"