Splunk Search

What's the difference between nomv and mvcombine?

nabeel652
Builder

Could someone please show the difference between nomv and mvcombine with some examples? What I have seen is that both work exactly the same way and delim parameter in mvcombine doesn't work as expected. Thanks

Labels (2)
0 Karma
1 Solution

renjith_nair
Legend

Reference : https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Mvcombine

 

The mvcombine command creates a multivalue version of the field you specify, as well as a single value version of the field. The multivalue version is displayed by default.

The single value version of the field is a flat string that is separated by a space or by the delimiter that you specify with the delim argument.

Try below searches one by one to understand the difference

1.

 

| makeresults count=10
| streamstats count

 

 2.

 

| makeresults count=10
| streamstats count
| mvcombine delim="," count

 

3.

 

| makeresults count=10
| streamstats count
| mvcombine delim="," count
| nomv count

 

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

Wise_Women
Engager

Great example, thanks!

0 Karma

renjith_nair
Legend

Reference : https://docs.splunk.com/Documentation/Splunk/8.1.1/SearchReference/Mvcombine

 

The mvcombine command creates a multivalue version of the field you specify, as well as a single value version of the field. The multivalue version is displayed by default.

The single value version of the field is a flat string that is separated by a space or by the delimiter that you specify with the delim argument.

Try below searches one by one to understand the difference

1.

 

| makeresults count=10
| streamstats count

 

 2.

 

| makeresults count=10
| streamstats count
| mvcombine delim="," count

 

3.

 

| makeresults count=10
| streamstats count
| mvcombine delim="," count
| nomv count

 

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...