Splunk Search

split multi value fields

aliroumani
Explorer

my dear friends,

I'm running the below search string that give me the following result:
index=qualys IP="" DNS="" cve="*" | table IP DNS cve | dedup IP DNS cve

result:
IP DNS cve
10.252.64.84 horemedysso2v.alrajhi.bank CVE-2010-4094, CVE-2010-0557, CVE-2009-4189, CVE-2009-3548, CVE-2009-3099

as you can see i have multi values in the cve filed seperated by comma.
my question is how to get the result to show as:
10.252.64.84 horemedysso2v.alrajhi.bank CVE-2010-4094
10.252.64.84 horemedysso2v.alrajhi.bank CVE-2010-0557
10.252.64.84 horemedysso2v.alrajhi.bank CVE-2009-4189
etc ...
meaning the i want the IP and DNS filed to be repeated with each single value of cve field and each one will be in new row.

thanks in advance

Tags (1)
0 Karma
1 Solution

sundareshr
Legend

Try this.

index=qualys IP="" DNS="" cve="*" | table IP DNS cve | makemv cve delim="," | mvexpand cve | dedup IP DNS cve

View solution in original post

sundareshr
Legend

Try this.

index=qualys IP="" DNS="" cve="*" | table IP DNS cve | makemv cve delim="," | mvexpand cve | dedup IP DNS cve

aliroumani
Explorer

perfecttttttttttttttttttttttttttttttttttttttt ...
thank you so much my friend.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...