Splunk Search

How to split results which are combined in a table and export to a csv?

theouhuios
Motivator

Hello

I have few results which look like below in a table command. They are the values which are extracted from the xml data (using rex and mv_add) which has multiple matches in a single event.

    name   number id        emplid
 1  
    aaa    123  897hjhuih   908908 
    bbb    234  hkhkjh      8nknkjn

2
    ahkjhkj      12453  897hj545huih    9089fgfg08 
    bbjdkljsb    23544  hkhk5454jh      8nknkjn54353

I want to split them to separate rows in table so that it considers the results separate while exporting to a csv.

  name        number  id             emplid
1 aaa         123     897hjhuih      908908
2 bbb         234     hkhkjh         8nknkjn
3 ahkjhkj     12453   897hj545huih   9089fgfg08
4 bbjdkljsb   23544   hkhk5454jh     8nknkjn54353

I tried mvexpand and xmlkv but they dont work. Any idea on how to achieve this? How did you approach it when you faced this issue

Tags (2)
1 Solution

theouhuios
Motivator

Got it to work. Used this http://answers.splunk.com/answers/123887/how-to-expand-multiple-multivalue-fields as an idea on how to solve this issue. Works beautifully.

View solution in original post

theouhuios
Motivator

Got it to work. Used this http://answers.splunk.com/answers/123887/how-to-expand-multiple-multivalue-fields as an idea on how to solve this issue. Works beautifully.

Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...