Splunk Search

Is it possible to use commands like makemv or nomv in data models?

Explorer

Is it possible to use the commands like makemv or nomv in data models? I am using regular expressions while building the datamodel for extracting some of the fields. One of the fields is a comma separated list in the format [a,b,c] or sometimes it is just [d]. I want a single field which will have possible values as a,b,c,d etc. And all this in the data model. Is it possible to achieve this ?

Explorer

You can do this with a calculated field, using an eval looking something like this:

mvfield = split(trim(commafield, "[]"), ",")
0 Karma

Contributor
0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!