Splunk Search

Substring of multivalues out ot multivalue field

geoffmartin
Engager

I'm trying to produce a multivalue field out of another multivalue field in my data model, and that's proven to be quite complicated. This is what I'm trying to achieve:

I have a multivalue field with application names, like:

Application:
   Word
   Excel
   PowerPoint

but since I have too many applications, I created a field submenu, in which you select the application first letter, and that filters the Application field. Then, out of the field above, I want to have one called "Submenu" with the following:

Submenu:
  W
  E
  P

And my tstats command do the rest on grouping and filtering. I tried to use substring but it doesn't work for multivalue fields, only the single-valued results of the field.

Any ideas?

0 Karma
1 Solution

somesoni2
Revered Legend

Try something like this

Your base search with field Application | eval SubMenu=Application | rex mode=sed field=SubMenu "s/(\w)(\w+)/\1/g" 

This will create a field SubMenu which will have same number of elements as Application and will contains just the first character from Application field values.

View solution in original post

somesoni2
Revered Legend

Try something like this

Your base search with field Application | eval SubMenu=Application | rex mode=sed field=SubMenu "s/(\w)(\w+)/\1/g" 

This will create a field SubMenu which will have same number of elements as Application and will contains just the first character from Application field values.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...