Greetings. My Splunk instance parses messages which has a JSON array type:
```
{ tags: ["info", "foo", "bar"] }
```
Let's say I want to search for events where precisely the second index of the tags field has the value "foo".
Using Multivalue fns left me with many questions:
More or less, as a polyglot programmer with a decade of experience, I found splunk operations on collections to be not just unintuitive, but counter intuitive. Beyond my explicit three question categories above, if compelled, let me know other best-known-practices around searching with array-ish fields 🙂
The SCS docs describe SPL2, not the SPL which is used in Splunk Enterprise and Splunk Cloud. In SPL there are no arrays. There are only multivalued fields.
The {} in 'tags{}' is just a part of the name. It's not an operator.