Splunk Search

How to Push a Value onto a MultiValue field

DerekKing
Path Finder

Hi,

I would like to be able to push a new value into a multi-valued field, from another field.

ie.
Field1="Derek"
mvfield2="Paul" "Dave" "Bill"

I'd like to be able to do something like mvfield2=mvfield2 + Field1

It looks like I maybe able to get around it by converting the multivalued field to a delimited string, adding the value of field1, then make a new multivalued field, but that seems a long way around what seems like something simple.

Does anyone have any better ideas ?

Thanks for the help
Derek

1 Solution

somesoni2
Revered Legend

You can use "mvappend" function with eval to do this in one step.

runanywhere sample

| gentimes start=-1 | eval field1="Dave" | eval field2=split("Rob,Bob,John",",") | table field* | eval field3=mvappend(field2,field1)

View solution in original post

somesoni2
Revered Legend

You can use "mvappend" function with eval to do this in one step.

runanywhere sample

| gentimes start=-1 | eval field1="Dave" | eval field2=split("Rob,Bob,John",",") | table field* | eval field3=mvappend(field2,field1)

DerekKing
Path Finder

Thanks - Not sure how I missed that!

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...