Splunk Search

why transaction does not create mv-fields?

marcokrueger
Path Finder

hi,
we have a transaction that doesn't generate mv-fields but a single field with blank-seperated values like starttime="123 345 4565" instead of the expected starttime="123" starttime="345" starttime="4556".

If we reduce the number of events it works fine.

best regards Marco

0 Karma
1 Solution

emaccaferri
Communicator

Try using mvlist=t

| transaction mvlist=t yourfield

View solution in original post

emaccaferri
Communicator

Try using mvlist=t

| transaction mvlist=t yourfield

marcokrueger
Path Finder

thank you, this works, if I make a "makemv" after it for every field I need as mv-field. If it is possible, I want to know under which conditions the transaction-command stops to generate mv-fields. I think it a strange behaviour that transaction do it sometimes so and sometimes other...

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...