Splunk Search

How do you create several multivalued fields?

MaryvonneMB
Path Finder

Hi all,

I have several events like this:

Field_A // Field_B // Field_C
A // 1 // z
A // 2 // z
B // 3 // y
B // 4 // x

I would like to create two multivalued fields from Field_B and Field_C relative to Field_A, like this:

Field_A // Field_B // Field_C
A // 1::2 // z
B // 3::4 // y::x

I try mvcombine, but it works only when I have Field_A and Field_B (or Field_A and Field_C). I didn't find how to use it with several fields.

Thank you for any help

0 Karma
1 Solution

niketn
Legend

@MaryvonneMB how about

  <yourMainSearch>
  | stats values(Field_B) as Field_B values(Field_C) as Field_C by Field_A
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

View solution in original post

niketn
Legend

@MaryvonneMB how about

  <yourMainSearch>
  | stats values(Field_B) as Field_B values(Field_C) as Field_C by Field_A
____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

MaryvonneMB
Path Finder

Thank you very much. I didn't though about stats values. I use mvjoin after to add separator I want and it works well 🙂

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...