This will give all log values irrespective of number logs. Trick is you need use "max_match" option with rex. | makeresults | eval value= "log:word1 log:word2 log:word3" | rex field=value max_match=0 "log:(?[^ ]+)" | mvexpand LogValue | fields LogValue | fields - _*
... View more