Splunk Search

Makemv command question

bcarr12
Path Finder

What is the best way to use the Makemv command when my logs have no delimiter? For example:

field=abcd

Where a, b, c, and d are unique values. I'm looking to get the count of each in my logs, but I am wondering what the best way would be to delimit them. The values will always be a single letter and the "end" of the field/value pair will be a space. For example:

field1=value1 field=abcd field3=value3

Thanks!

0 Karma
1 Solution

elliotproebstel
Champion

I'd add a delimiter (like a comma) with a regex and then makemv afterwards:

| stats count | eval this="abcd" | rex field=this mode=sed "s/(.)/\1,/g" | makemv delim="," this

View solution in original post

0 Karma

elliotproebstel
Champion

I'd add a delimiter (like a comma) with a regex and then makemv afterwards:

| stats count | eval this="abcd" | rex field=this mode=sed "s/(.)/\1,/g" | makemv delim="," this

0 Karma

bcarr12
Path Finder

Thank you! This was exactly what I needed to do. Much appreciated.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...