Search Reference

 


nomv

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

nomv

Synopsis

Changes a specified multi-value field into a single-value field at search time.

Syntax

nomv field

Description

Converts values of the specified multi-valued field into one single value (overrides multi-value field configurations set in fields.conf).

Examples

Example 1: For sendmail events, combine the values of the senders field into a single value; then, display the top 10 values.

eventtype="sendmail" | nomv senders | top senders

See also

makemv, mvcombine, mvexpand, convert

This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.