Splunk Search

How to match string in multi value field?

james_n
Path Finder

Hi experts,

I have a filed called names as shown below, if i search with first line of strings then search returning the complete filed event but not second and third line of filed strings. I used | eval names= mvfilter(names="32") and also | eval names= mvfilter(match("32", names)) but not worked for me. Please help me on this, Thanks in advance.

names
1121 - sample name
3247 - sample names
9876 - simple name

required out put: if I search with names=1121* or names=3247* or names=9876* then complete event has to be returned.i,e as i shown above.

0 Karma

Senak
Loves-to-Learn Everything

Hi,

Your match() syntax in just not good.
It should be 

 

 | eval names= mvfilter(match(names,"32"))

 

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I think mvfind may help you.

| eval names = if ( isnull ( mvfind ( names, "32" ) ), null, names )
---
If this reply helps you, Karma would be appreciated.

james_n
Path Finder

@richgalloway thanks for the quick response, its working fine but above mentioned value(32) comes from drop down using token, the problem is when i select any value in the drop down list its working fine but if i select * which is default value of that drop down at that time shown an error. plz help on this, once again thanks.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The second argument to mvfind (and match) must be a valid regular expression. * is not valid, but .* is. Try that.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...