Splunk Search

How to extract this field which may have multiple values separated by pipes? (offerId="ABC_79|ABC_80|ABC_81|ABC_56" or offerId="ABC_79")

Kukkadapu
Path Finder

Hi,

Can you help me with the search to extract the following? The offerId may come in the log as offerId="ABC_79|ABC_80|ABC_81|ABC_56" separated by pipes (if there are multiple records) or just offerId="ABC_79" (if there is just one offer).

So how do I extract the offerId's to a new field offerName?

The final output would be:
OfferName:
ABC_79
ABC_80
ABC_81
ABC_56

Thanks.

0 Karma
1 Solution

somesoni2
Revered Legend

Something like this

your base search | eval offerName=split(offer_id,"|") 

OR

your base search | makemv offerId delim="|"

View solution in original post

somesoni2
Revered Legend

Something like this

your base search | eval offerName=split(offer_id,"|") 

OR

your base search | makemv offerId delim="|"

Kukkadapu
Path Finder

Perfect! It worked . Thanks for your time 🙂

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...