Splunk Search

How do you split two string values joined in one field?

mdmaala
Communicator

hi!

Under the field Username, I have two lists, Machine1 and Machine2

I want to split this into two separate columns Machine 1 and Machine2

how can I do this? Thanks!

I tried using my search...| rex field=Username "(?Machine1)(?Machine2)", but it's not working.

Tags (1)
0 Karma

woodcock
Esteemed Legend

Like this:

... | eval Machine1 = mvindex(Username, 0), Machine2 = mvindex(Username, 1)
0 Karma

spavin
Path Finder

Can you give us a sample field to work with? Does it look like: Machine 1 Machine 2?

0 Karma

mdmaala
Communicator

the table looks like this:

| Username |
Machine 1
Machine 2

I want to separate the username field into Machine1 and Machine2

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...