mvexpand
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
mvexpand
Synopsis
Expands the values of a multi-value field into separate events for each value of the multi-value field.
Syntax
mvexpand field
Description
For each result with the specified field, create a new result for each value of that field in that result if it a multivalue field.
Examples
Example 1: Create new events for each value of multi-value field, "foo".
... | mvexpand foo
See also
This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.