I need your help.
I have a field which contains multivalue.
I need a way to only display events that have foo and bar in this field. I tried to count the values and filter them accordingly but it doesn't work.
your search |where isnotnull(mvfind(field_name,"foo")) AND isnotnull(mvfind(field_name,"bar"))
Please note that the argument to mvfind is REGEX . So based on your field value, you may combine that with regex as well
Reference : https://docs.splunk.com/Documentation/Splunk/7.3.1/SearchReference/MultivalueEvalFunctions#mvfind.28...
View solution in original post