Splunk Search

How to create a multivalue FieldC with the common values found in multivalue fields FieldA and FieldB?

vbumgarner
Contributor

I have two fields that are multivalue, and I need to know what they have in common.

For instance, given:
a=[1,2,3]
b=[2,3,4]
I want to create:
c=[2,3]

I made it work with some crazy mvexpand, but I'd really rather not do that. I tried to make it work using a combination of mvfilter and mvfind, but couldn't make that work, either.

Any thoughts on how to do this more efficiently?

Cheers.

0 Karma

fdi01
Motivator

you can use also mvindex and mvzip command to do it.

the if() or case() and match( ) functions are used to build your condictions fine on.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...