Splunk Search

Splitting a multi value field in configuration files

asieira
Path Finder

I have a JSON data source in which one of the fields contains a comma separated list of values. Is there a way to use configuration files (rather than using split during the search as indicated in http://answers.splunk.com/answers/53555/splitting-a-multi-valued-field.html) to ensure that this field is extracted as a multi-value field?

Here's one example event:

{ field1=10, field2="blah,bleh,blih" }

I would like field2 to be extracted as a multi-value field with the values blah, bleh and blihwithout the need to explicitly split the value in each search.

0 Karma
1 Solution

somesoni2
Revered Legend

The easiest option would to be setup a calculated field to do this splitting automatically (through configuration files) for field 2.

See this http://docs.splunk.com/Documentation/Splunk/6.2.2/Knowledge/definecalcfields

Anything you can do in an eval field can be done here.

View solution in original post

somesoni2
Revered Legend

The easiest option would to be setup a calculated field to do this splitting automatically (through configuration files) for field 2.

See this http://docs.splunk.com/Documentation/Splunk/6.2.2/Knowledge/definecalcfields

Anything you can do in an eval field can be done here.

asieira
Path Finder

This allowed me to do exactly what I needed. Thank you!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...