Splunk Search

why transaction does not create mv-fields?

marcokrueger
Path Finder

hi,
we have a transaction that doesn't generate mv-fields but a single field with blank-seperated values like starttime="123 345 4565" instead of the expected starttime="123" starttime="345" starttime="4556".

If we reduce the number of events it works fine.

best regards Marco

0 Karma
1 Solution

emaccaferri
Communicator

Try using mvlist=t

| transaction mvlist=t yourfield

View solution in original post

emaccaferri
Communicator

Try using mvlist=t

| transaction mvlist=t yourfield

marcokrueger
Path Finder

thank you, this works, if I make a "makemv" after it for every field I need as mv-field. If it is possible, I want to know under which conditions the transaction-command stops to generate mv-fields. I think it a strange behaviour that transaction do it sometimes so and sometimes other...

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...