Splunk Search

Multivalue Field Filterung search

mklhs
Path Finder

Hello,

I need your help.
I have a field which contains multivalue.
Example:
Table


Foo


in cash


foo
in cash


I need a way to only display events that have foo and bar in this field. I tried to count the values and filter them accordingly but it doesn't work.

0 Karma
1 Solution

renjith_nair
Legend

@mklhs ,

Try

your search |where isnotnull(mvfind(field_name,"foo")) AND isnotnull(mvfind(field_name,"bar"))

Please note that the argument to mvfind is REGEX . So based on your field value, you may combine that with regex as well

Reference : https://docs.splunk.com/Documentation/Splunk/7.3.1/SearchReference/MultivalueEvalFunctions#mvfind.28...

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

@mklhs ,

Try

your search |where isnotnull(mvfind(field_name,"foo")) AND isnotnull(mvfind(field_name,"bar"))

Please note that the argument to mvfind is REGEX . So based on your field value, you may combine that with regex as well

Reference : https://docs.splunk.com/Documentation/Splunk/7.3.1/SearchReference/MultivalueEvalFunctions#mvfind.28...

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...