Splunk Search

## Re design fields and values

Path Finder

I have fields as shown below:

``````_time                  field1              field2
2020-05-12             40-35-32             A-B-C
2020-05-13             63-28-74             A-B-C
``````

need to change the events to be:

``````    _time               field1        field2
2020-05-12             40             A
2020-05-12             35             B
2020-05-12             32             C
2020-05-13             63             A
2020-05-13             28             B
2020-05-13             74             C
``````

Appreciate your help fellows Splunkers 😄

Tags (4)
1 Solution
Champion

Hi

Check this

``````| makeresults
| eval _time="2020-05-12",field1="40-35-32",field2="A-B-C"
| append
[| makeresults
| eval _time="2020-05-13",field1="63-28-74",field2="A-B-C"]
| eval field1=split(field1,"-"),field2=split(field2,"-")
| eval temp=mvzip(field1,field2)
| mvexpand temp
| eval temp=split(temp,",")
| eval field1=mvindex(temp,0),field2=mvindex(temp,1)
| fields - temp
``````
Champion

Hi

Check this

``````| makeresults
| eval _time="2020-05-12",field1="40-35-32",field2="A-B-C"
| append
[| makeresults
| eval _time="2020-05-13",field1="63-28-74",field2="A-B-C"]
| eval field1=split(field1,"-"),field2=split(field2,"-")
| eval temp=mvzip(field1,field2)
| mvexpand temp
| eval temp=split(temp,",")
| eval field1=mvindex(temp,0),field2=mvindex(temp,1)
| fields - temp
``````
Path Finder

Thank you Brother @vnravikumar , That was so fast

.conf21 CFS Extended through 5/20!

### Don't miss your chance to share your Splunk wisdom in-person or virtually at .conf21!Call for Speakers hasbeen extended throughThursday, 5/20! Submit Now! >

Get Updates on the Splunk Community!