Splunk Search

why transaction does not create mv-fields?

marcokrueger
Path Finder

hi,
we have a transaction that doesn't generate mv-fields but a single field with blank-seperated values like starttime="123 345 4565" instead of the expected starttime="123" starttime="345" starttime="4556".

If we reduce the number of events it works fine.

best regards Marco

0 Karma
1 Solution

emaccaferri
Communicator

Try using mvlist=t

| transaction mvlist=t yourfield

View solution in original post

emaccaferri
Communicator

Try using mvlist=t

| transaction mvlist=t yourfield

marcokrueger
Path Finder

thank you, this works, if I make a "makemv" after it for every field I need as mv-field. If it is possible, I want to know under which conditions the transaction-command stops to generate mv-fields. I think it a strange behaviour that transaction do it sometimes so and sometimes other...

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...