Splunk Search

Splitting a multi value field in configuration files

asieira
Path Finder

I have a JSON data source in which one of the fields contains a comma separated list of values. Is there a way to use configuration files (rather than using split during the search as indicated in http://answers.splunk.com/answers/53555/splitting-a-multi-valued-field.html) to ensure that this field is extracted as a multi-value field?

Here's one example event:

{ field1=10, field2="blah,bleh,blih" }

I would like field2 to be extracted as a multi-value field with the values blah, bleh and blihwithout the need to explicitly split the value in each search.

0 Karma
1 Solution

somesoni2
Revered Legend

The easiest option would to be setup a calculated field to do this splitting automatically (through configuration files) for field 2.

See this http://docs.splunk.com/Documentation/Splunk/6.2.2/Knowledge/definecalcfields

Anything you can do in an eval field can be done here.

View solution in original post

somesoni2
Revered Legend

The easiest option would to be setup a calculated field to do this splitting automatically (through configuration files) for field 2.

See this http://docs.splunk.com/Documentation/Splunk/6.2.2/Knowledge/definecalcfields

Anything you can do in an eval field can be done here.

asieira
Path Finder

This allowed me to do exactly what I needed. Thank you!

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...