
nomv
Description
Converts values of the specified multivalue field into one single value. Overrides the configurations for the multivalue field that are set in the fields.conf
file.
Syntax
nomv <field>
Required arguments
- field
- Syntax: <field>
- Description: The name of a multivalue field.
Usage
The nomv
command is a distributable streaming command. See Command types.
You can use evaluation functions and statistical functions on multivalue fields or to return multivalue fields.
Examples
Example 1:
For sendmail events, combine the values of the senders field into a single value. Display the top 10 values.
eventtype="sendmail" | nomv senders | top senders
See also
Commands:
makemv
mvcombine
mvexpand
convert
Functions:
Multivalue eval functions
Multivalue stats and chart functions
split
PREVIOUS mvexpand |
NEXT outlier |
This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.6.0, 6.6.1, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13, 7.1.0, 7.1.1, 7.1.3, 7.1.5, 7.1.10, 6.3.1, 7.1.2, 7.1.8, 7.1.9, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.1.0, 8.1.1, 7.1.4, 7.1.6, 7.1.7
Feedback submitted, thanks!