I am trying to get the following results for date, email and answer with the other data into separate rows:
Results I am getting:
Results I need to see:
index=someindex | eval status=case(like(_raw, "%NO%"), "NO", like(_raw, "%YES%"), "YES")| lookup fall2020OnCampusStudents email OUTPUT class, name, ID, className, classNumber, college| search class!=""| table Date, name, email, ID, status, class, className, classNumber, college| sort college, email, class| rename email AS "Email", status AS "Answer", class AS "Classes", className as "Class Name", classNumber as "Class Number", college as "College"
I have tried using mvexpand, but it will only take the first line of each field. I am still trying to understand other techniques, but still learning.
Solved the issue with Splunks Help:
View solution in original post