I have a dataset with a multiline field called Logs. The field typically has values like the below,
"mId": "Null",
"deviceID": "a398Z389j",
"cSession": "443",
"cWeb": "443",
"uWeb": "Mixed",
"s": "Steak",
"Ing": [
"1-555-5555555",
"1-888-8888888"
],
"Sem": [
"Warehouse@Forest.box"
]
I'd like to make it so I can identify the values within "Ing" and easily search where a specific value is in "Ing" for other events. I was able to break it out and split on the comma and then look at the index number 6 but this only returns the 1st item, where in most events there are multiple (upwards of 10) items.
| eval a = mvindex(split(Logs,","), 6)
"Ing": [
"1-555-5555555"
Thoughts on how to get a complete list of the items in Ing?
... View more