Splunk Search

How to extract this field which may have multiple values separated by pipes? (offerId="ABC_79|ABC_80|ABC_81|ABC_56" or offerId="ABC_79")

Path Finder

Hi,

Can you help me with the search to extract the following? The offerId may come in the log as offerId="ABC_79|ABC_80|ABC_81|ABC_56" separated by pipes (if there are multiple records) or just offerId="ABC_79" (if there is just one offer).

So how do I extract the offerId's to a new field offerName?

The final output would be:
OfferName:
ABC_79
ABC_80
ABC_81
ABC_56

Thanks.

0 Karma
1 Solution

Revered Legend

Something like this

your base search | eval offerName=split(offer_id,"|") 

OR

your base search | makemv offerId delim="|"

View solution in original post

Revered Legend

Something like this

your base search | eval offerName=split(offer_id,"|") 

OR

your base search | makemv offerId delim="|"

View solution in original post

Path Finder

Perfect! It worked . Thanks for your time 🙂

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!