Splunk Search

Filtering multi-value (or array) field with multi-value input

moomber
Observer

Hi I tried searching all over but can't seem to find a good approach to do this. Basically, I have a multiselect input that needs to be used to filter a search, on a field that an array. For instance:

multiselect input can be "value1", "value2", and the field from the search be a list or array of "value1", "value2", "value3" ..etc.

how can we check and filter out events with fields that do not contain all the elements from the multiselect input ?

Thanks in advance.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...
OSZAR »