Splunk Search

MV field split by comma and not line break

mdsnmss
SplunkTrust
SplunkTrust

I have a group of multivalue fields that are listed with linebreaks . I'm looking to remove the line breaks from one field and have them separated by comma instead. Here is the structure and what I am looking for:

Original:
FieldA | FieldB |FieldC |FieldD |FieldE
Val1   | val1   | val1  | val1  | val1
       | val2   | val2
       | val3   | val3
       | etc    | etc
Val2   | val1   | val1  | val1  | val1
       | val2   | val2
       | val3   | val3
       |etc     |etc

Desired:
FieldA | FieldB             |FieldC |FieldD |FieldE
Val1   | val1,val2,val3,etc | val1  | val1  | val1
                            | val2
                            | val3
                            | etc
Val2   | val1,val2,val3,etc | val1  | val1  | val1
                            | val2
                            | val3
                            | etc

Sorry if the formatting is a bit confusing. I tried using "makemv FieldB delim=","" and got the field values to appear on the same row but with a space instead of a comma. Any ideas?

Tags (3)
1 Solution

mdsnmss
SplunkTrust
SplunkTrust

I got it. Use mvjoin in an eval.

| eval FieldB=mvjoin(FieldB,",")

View solution in original post

mdsnmss
SplunkTrust
SplunkTrust

I got it. Use mvjoin in an eval.

| eval FieldB=mvjoin(FieldB,",")
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...