Splunk Search

Searching against an mvappend generated field

ddrillic
Ultra Champion

We created in props.confthe following -

EVAL-mod_code = mvappend(modifier_code, modifier_code2, modifier_code3, modifier_code4, modifier_code5)

The mod_code field is now available but I don't know how to search against it.

index=claims mod_code=U3

doesn't seem to work.

Any ideas?

Tags (1)
0 Karma
1 Solution

sundareshr
Legend

Try this (the values in mvappend need to be within quotes)

index=claims | where mvfind(mod_code, "3")>=0 | ...

View solution in original post

0 Karma

sundareshr
Legend

Try this (the values in mvappend need to be within quotes)

index=claims | where mvfind(mod_code, "3")>=0 | ...
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...