Splunk Search

Extracting values from multivalued field and merging


For example :

these are some part of my logs:

sender= xyz(receiver=a, receiver =b) 

sender= abc(receiver=a,receiver =d)


....more entries

And result should be something like:

sender=xyz receiver=a

sender=xyz receiver=b

sender=abc receiver=c

sender=abc receiver=d

and I am using remote button as input

So whenever i give input of receiver=a

it should give me a table like

sender = abc.       1

sender= xyz         2

Need help! To write query 😞


Labels (4)
0 Karma

Esteemed Legend

Hi @Dhruvi ,

try something like this:

This is the first:

| rex field=sender "^(?<my_sender>[^\(]*)"
| rex max_match=10 field=sender "receiver\s*\=(?<receiver>\w*)"
| mvexpand receiver
| table my_sender receiver

This is the second:

| rex field=sender "^(?<my_sender>[^\(]*)"
| rex max_match=10 field=sender "receiver\s*\=(?<receiver>\w*)"
| mvexpand receiver
| stats count BY receiver





0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...