Splunk Search

Help with SPL Splunk part 2

uagraw01
Motivator

To provide further from yesterday's SPL query. I am facing huge events in multivalues. I want to break in a single event. How can I achieve it.

My current events are look like as below.

uagraw01_0-1666334392521.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @uagraw01,

let me better understand you need:

you have al these long error messages and you have them in a multivalue,you want to have each of them in a single event, is it correct?

Anyway, the method to transform a multivale in single events is mvexpand command (https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Mvexpand).

If you could share your final search I could be more precise in mvexpand use.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...

Secure Your Future: Mastering Upgrade Readiness for Splunk 10

Spotlight: The Splunk Health Assistant Add-On  The Splunk Health Assistant Add-On is your ultimate companion ...

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...