Splunk Search
Highlighted

makemv command with tokenizer

Explorer

i, One of my value in table is being passed as an Boolean expression as below

(assignmentgroup = 1213AppDevelopment1 OR assignmentgroup = App-Testing OR assignmentgroup = App Support OR assignmentgroup = App:Support OR assignmentgroup = App&$+*Support assignment_group = AppSupport)

I'm trying to use the | makemv tokenizer= to make the above to be extracted as multivalues as below

1213App_Developmen1
App-Testing
App Support
App:Support
App&$+*Support
AppSupport

And then use mxexpand to appy other table values to the expanded fields.

Can anyone help me with the Regex to do so.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.