Hello,
I need your help.
I have a field which contains multivalue.
Example:
Table
Foo
in cash
foo
in cash
I need a way to only display events that have foo and bar in this field. I tried to count the values and filter them accordingly but it doesn't work.
@mklhs ,
Try
your search |where isnotnull(mvfind(field_name,"foo")) AND isnotnull(mvfind(field_name,"bar"))
Please note that the argument to mvfind is REGEX
. So based on your field value, you may combine that with regex as well
Reference : https://docs.splunk.com/Documentation/Splunk/7.3.1/SearchReference/MultivalueEvalFunctions#mvfind.28...
@mklhs ,
Try
your search |where isnotnull(mvfind(field_name,"foo")) AND isnotnull(mvfind(field_name,"bar"))
Please note that the argument to mvfind is REGEX
. So based on your field value, you may combine that with regex as well
Reference : https://docs.splunk.com/Documentation/Splunk/7.3.1/SearchReference/MultivalueEvalFunctions#mvfind.28...