Splunk Search

Splitting raw field after transaction

moinyuso96
Path Finder

I used transaction to combine 2 rows of raw fields:

raw

4015_ABCD, Start, 8/11/2020 5:37:10 PM, 12345

4015_ABCD, Complete, 8/11/2020 5:37:30 PM, 12345

4015_ABCD, Start, 8/12/2020 10:23:34 AM, 12345

1113_EFGH, Start, 8/12/2020 12:00:00 PM, 67890

1113_EFGH, Complete, 8/12/2020 1:00:00 PM, 67890

 

Is there a simple way to split the raw field into "raw1" and "raw2" as below (preferably without using rex)?

rawraw1raw2

4015_ABCD, Start, 8/11/2020 5:37:10 PM, 12345

4015_ABCD, Complete, 8/11/2020 5:37:30 PM, 12345

4015_ABCD, Start, 8/11/2020 5:37:10 PM, 123454015_ABCD, Complete, 8/11/2020 5:37:30 PM, 12345
4015_ABCD, Start, 8/12/2020 10:23:34 AM, 123454015_ABCD, Start, 8/12/2020 10:23:34 AM, 12345 

1113_EFGH, Start, 8/12/2020 12:00:00 PM, 67890

1113_EFGH, Complete, 8/12/2020 1:00:00 PM, 67890

1113_EFGH, Start, 8/12/2020 12:00:00 PM, 678901113_EFGH, Complete, 8/12/2020 1:00:00 PM, 67890
Labels (2)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

Using mvindex on the multivalue raw field

| eval raw1=mvindex(raw,0), raw2=mvindex(raw,1)

View solution in original post

bowesmana
SplunkTrust
SplunkTrust

Using mvindex on the multivalue raw field

| eval raw1=mvindex(raw,0), raw2=mvindex(raw,1)

bowesmana
SplunkTrust
SplunkTrust

Also just FYI - as a generic solution to splitting multivalue fields where you don't always know you will have 2 fields, you can do this sort of thing

| foreach 0 1 2 3 4 5 [ eval raw<<FIELD>>=mvindex(raw,<<FIELD>>) ]

which would split up to 6 values of a multi-value field into raw0, raw1, raw2 etc.

 

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...