Search Reference

 


mvexpand

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

mvexpand

Synopsis

Expands the values of a multi-value field into separate events for each value of the multi-value field.

Syntax

mvexpand field

Description

For each result with the specified field, create a new result for each value of that field in that result if it a multivalue field.

Examples

Example 1: Create new events for each value of multi-value field, "foo".

... | mvexpand foo


See also

makemv, mvcombine, nomv

This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.