Splunk Search

Multi events

I have an event as below

Names

"John|James|Jude|Jenni|bond|Tom"

How do i get each name as separate event.

0 Karma

SplunkTrust
SplunkTrust

Split the field then expand it into multiple events.

... | eval Names=split(Names, "|") | mvexpand Names | ...
---
If this reply helps you, an upvote would be appreciated.
0 Karma