Splunk Search

What's the difference between nomv and mvcombine?

nabeel652
Builder

Could someone please show the difference between nomv and mvcombine with some examples? What I have seen is that both work exactly the same way and delim parameter in mvcombine doesn't work as expected. Thanks

Labels (3)
0 Karma
1 Solution

renjith_nair
Legend

Reference : https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Mvcombine

 

The mvcombine command creates a multivalue version of the field you specify, as well as a single value version of the field. The multivalue version is displayed by default.

The single value version of the field is a flat string that is separated by a space or by the delimiter that you specify with the delim argument.

Try below searches one by one to understand the difference

1.

 

| makeresults count=10
| streamstats count

 

 2.

 

| makeresults count=10
| streamstats count
| mvcombine delim="," count

 

3.

 

| makeresults count=10
| streamstats count
| mvcombine delim="," count
| nomv count

 

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

Wise_Women
Engager

Great example, thanks!

0 Karma

renjith_nair
Legend

Reference : https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Mvcombine

 

The mvcombine command creates a multivalue version of the field you specify, as well as a single value version of the field. The multivalue version is displayed by default.

The single value version of the field is a flat string that is separated by a space or by the delimiter that you specify with the delim argument.

Try below searches one by one to understand the difference

1.

 

| makeresults count=10
| streamstats count

 

 2.

 

| makeresults count=10
| streamstats count
| mvcombine delim="," count

 

3.

 

| makeresults count=10
| streamstats count
| mvcombine delim="," count
| nomv count

 

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...