Multivalue Fields is a Splunk Education course focused on working with fields that contain multiple values within a single event.
What You Will Learn
- Understand how Splunk stores and displays multivalued fields in search results
- Use makemv, mvsort, mvzip, and related commands to manipulate multivalued fields
- Extract multivalued fields using regex and delimiter-based field extraction
- Apply mvexpand to expand multivalued fields into separate events for reporting
- Use values() and list() statistical functions with multivalued field data
Who Should Attend
Splunk power users and analysts who work with log sources that produce multivalued fields.
Prerequisites
Solid understanding of Splunk search fundamentals and transforming commands.





