Splunk Search

How do I expand this multivalue field?

Builder

All,

We are currently getting a log like this from our F5.

 xff="1.2.3.4, 4.3.2.1, 4.2.2.2, 9.8.7.1" 

I'd like to mvexpand it. I assumed I could just |mvexpand xff, but that doesn't not work.

Any idea how I would tackle this?

0 Karma

Esteemed Legend

You have to make it a multivalued field first, like this:

... | makemv delim="," xff | mvexpand xff

Legend

Try this

... | eval x=split(xff, ",") | mvexpand x
0 Karma