Splunk Search

mvindex - How to separate results?

dkeck
Influencer

Hi,

I have this code:

|rex max_match=0 field=values "value\":\"(?<example>(.*?))\""
|eval example=mvindex(example,0,1)

result is this :

*field*        *example*
action     failure success 

Is it possible to separate "failure" and "success" into 2 rows, so actually add a line break?
or at least add a ";" or ","?

Thank you

0 Karma
1 Solution

jeffland
SplunkTrust
SplunkTrust

There are probably many ways to do that. You could use mvexpand:

|rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" | mvexpand example

It should give you one line per value in your multivalue field while duplicating all other values.

View solution in original post

chimell
Motivator

Hi
try this search code

|rex max_match=0 field=values "value\":\"(?<example>(.*?))\""| eval example=split(example ," ") | mvexpand example 
0 Karma

ngatchasandra
Builder

Hi dkeck,

If you want to add " ," or ";" to use makemv command like follow:

  |rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" |eval example=mvindex(example,0,1) | makemv delim="," example

If you want to add linebreak you can try to use mvjoin function:

|rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" |eval example=mvindex(example,0,1) | eval example=mvjoin(example," ") | rex mode=sed field=example "s/,/\n/g"

mvjoin(example," ") because values of example are separated by space

0 Karma

jeffland
SplunkTrust
SplunkTrust

There are probably many ways to do that. You could use mvexpand:

|rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" | mvexpand example

It should give you one line per value in your multivalue field while duplicating all other values.

dkeck
Influencer

Thank you, but thats not what I want.

I want to keep the mvfield add just and some kind of separation to it, to make it more readable.

0 Karma

jeffland
SplunkTrust
SplunkTrust

Ah, I thought you wanted "two rows" in your table, but I assume you meant "two rows" inside your one result row, one for each value of your multivalue field.
That should be the case by default, so I'm not quite sure why your table has the two rex matches side by side. You could try this:

| rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" | eval example=replace(example, "\s", ";\s")

It should add a semicolon into your text.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...