Splunk Search

How to have resutls from | stats values(field) shown in individual rows

andres91302
Communicator
Hello guys I am trying to download a CVS file from a query that comes after a | stats values(field) command, thus this function organizes the data in a single row and when I open my cvs file all hell breaks loose... can you please teach me how to have the values shown in an inidivual row please? thank you
Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

mvexpand can be used to split multi-value fields into separate events (rows)

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...