I am trying to get the following results for date, email and answer with the other data into separate rows:
Results I am getting:
Results I need to see:
Search Query:
index=someindex
| eval status=case(like(_raw, "%NO%"), "NO", like(_raw, "%YES%"), "YES")
| lookup fall2020OnCampusStudents email OUTPUT class, name, ID, className, classNumber, college
| search class!=""
| table Date, name, email, ID, status, class, className, classNumber, college
| sort college, email, class
| rename email AS "Email", status AS "Answer", class AS "Classes", className as "Class Name", classNumber as "Class Number", college as "College"
I have tried using mvexpand, but it will only take the first line of each field. I am still trying to understand other techniques, but still learning.
Solved the issue with Splunks Help:
Solved the issue with Splunks Help: