Splunk Search

split multi value fields

aliroumani
Explorer

my dear friends,

I'm running the below search string that give me the following result:
index=qualys IP="" DNS="" cve="*" | table IP DNS cve | dedup IP DNS cve

result:
IP DNS cve
10.252.64.84 horemedysso2v.alrajhi.bank CVE-2010-4094, CVE-2010-0557, CVE-2009-4189, CVE-2009-3548, CVE-2009-3099

as you can see i have multi values in the cve filed seperated by comma.
my question is how to get the result to show as:
10.252.64.84 horemedysso2v.alrajhi.bank CVE-2010-4094
10.252.64.84 horemedysso2v.alrajhi.bank CVE-2010-0557
10.252.64.84 horemedysso2v.alrajhi.bank CVE-2009-4189
etc ...
meaning the i want the IP and DNS filed to be repeated with each single value of cve field and each one will be in new row.

thanks in advance

Tags (1)
0 Karma
1 Solution

sundareshr
Legend

Try this.

index=qualys IP="" DNS="" cve="*" | table IP DNS cve | makemv cve delim="," | mvexpand cve | dedup IP DNS cve

View solution in original post

sundareshr
Legend

Try this.

index=qualys IP="" DNS="" cve="*" | table IP DNS cve | makemv cve delim="," | mvexpand cve | dedup IP DNS cve

aliroumani
Explorer

perfecttttttttttttttttttttttttttttttttttttttt ...
thank you so much my friend.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...