Splunk Search

How to extract numbers from multivalue fields

cindygibbs_08
Communicator

Hello Guys I have a sort of quick question that has been challanging me.

 

I use this SPL to extract some info

 

 

| stats values(*) as * by CLIENTE_OUTPOST

 

 

Sometimes I use list sometimes I use values... and I want to be able to extract all values in the multivalue field "PROMOS" in a new field called "ADDED" this is an example:

 

from this:

 

CLIENT_OUTPOSTPROMOSDATEVOUCHER
LIZZA_90UIK_IO
87585
A_IDYD
78545
10584
18-05-2021XX-PO-89

 

I want this:

CLIENT_OUTPOSTPROMOSDATEVOUCHERADDED
LIZZA_90UIK_IO
87585
A_IDYD
78545
10584
18-05-2021XX-PO-8987585
78545
10584



I will be so thankfull if you can help me out, just for reference I will eaither have strings with characters or strings that are numbers... but i have tried mvfilter, rex without any luck thank you so much guys!

 

Love,

 

Cindy

Labels (1)
0 Karma
1 Solution

venkatasri
SplunkTrust
SplunkTrust

Hi @cindygibbs_08 can you try this?

<your_search>
| eval promos_delim=mvjoin(PROMOS,",")
| rex field=promos_delim max_match=0 "(?<Added>\d+)" 
| table PROMOS Added 

---

An upvote would be appreciated and Accept solution if this reply helps!

View solution in original post

venkatasri
SplunkTrust
SplunkTrust

Hi @cindygibbs_08 can you try this?

<your_search>
| eval promos_delim=mvjoin(PROMOS,",")
| rex field=promos_delim max_match=0 "(?<Added>\d+)" 
| table PROMOS Added 

---

An upvote would be appreciated and Accept solution if this reply helps!

cindygibbs_08
Communicator

@venkatasri  the best! 10/10 sorry for the delay 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...