Splunk Search

How to convert a field value of single line to displayed as multilines?

pavanae
Builder

Hi Splunkers, 

I have defined a filed as follows using eval condition 

 

 

 

| eval body = "Sample Example :-" . 
" ---- " . " HOST INFORMATION: " . 
" ---- Source Network Address: " . src . 
" ---- Source Network Hostname: " . srcdns_hostname . 
" ---- " . " END "

 

 

 

which produces the result as follows 

sample.PNG

Now, I would like to change the above result into the below format how can I achieve that 

 

 

 

Sample Example :- 
HOST INFORMATION: 
Source Network Address: 1.1.3.5 
Source Network Hostname: ABCD.net
END 

 

 

 

 

Labels (5)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

An alternative to embedding newlines into the eval, you can do it with mvappend, e.g.

| eval body = mvappend("Sample Example :-","HOST INFORMATION: ", "Source Network Address: ".src, "Source Network Hostname: ". srcdns_hostname, "END ")

Note that this results in a different field compared to @richgalloway solution - that form will give you a single value field with embedded newlines, whereas mvappend gives you a multi-value field with each line a separate value of the field.

 

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

An alternative to embedding newlines into the eval, you can do it with mvappend, e.g.

| eval body = mvappend("Sample Example :-","HOST INFORMATION: ", "Source Network Address: ".src, "Source Network Hostname: ". srcdns_hostname, "END ")

Note that this results in a different field compared to @richgalloway solution - that form will give you a single value field with embedded newlines, whereas mvappend gives you a multi-value field with each line a separate value of the field.

 

richgalloway
SplunkTrust
SplunkTrust

 Insert newlines in your eval using CTRL-Enter.

| eval body = "Sample Example :- 
HOST INFORMATION: 
Source Network Address: " . src . "
Source Network Hostname: " . srcdns_hostname . " 
END "

 

---
If this reply helps you, Karma would be appreciated.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...