Splunk Search

makemv command with tokenizer

Explorer

i, One of my value in table is being passed as an Boolean expression as below

(assignmentgroup = 1213AppDevelopment1 OR assignmentgroup = App-Testing OR assignmentgroup = App Support OR assignmentgroup = App:Support OR assignmentgroup = App&$+*Support assignment_group = AppSupport)

I'm trying to use the | makemv tokenizer= to make the above to be extracted as multivalues as below

1213App_Developmen1
App-Testing
App Support
App:Support
App&$+*Support
AppSupport

And then use mxexpand to appy other table values to the expanded fields.

Can anyone help me with the Regex to do so.

0 Karma