Splunk Search

How to extract this field which may have multiple values separated by pipes? (offerId="ABC_79|ABC_80|ABC_81|ABC_56" or offerId="ABC_79")

Kukkadapu
Path Finder

Hi,

Can you help me with the search to extract the following? The offerId may come in the log as offerId="ABC_79|ABC_80|ABC_81|ABC_56" separated by pipes (if there are multiple records) or just offerId="ABC_79" (if there is just one offer).

So how do I extract the offerId's to a new field offerName?

The final output would be:
OfferName:
ABC_79
ABC_80
ABC_81
ABC_56

Thanks.

0 Karma
1 Solution

somesoni2
Revered Legend

Something like this

your base search | eval offerName=split(offer_id,"|") 

OR

your base search | makemv offerId delim="|"

View solution in original post

somesoni2
Revered Legend

Something like this

your base search | eval offerName=split(offer_id,"|") 

OR

your base search | makemv offerId delim="|"

Kukkadapu
Path Finder

Perfect! It worked . Thanks for your time 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...