Hey guys,
Splunk value pairs are not being automatically parsed. for example
USER=obama
AGE=18
should automatically fieldify "USER", "AGE". but not doing that. I check different conf for any changes in default/props.conf & default/transforms.conf, but can't find any issues.
Any ideas? gurus?
Hey !
You can deal with Transforms/Extract.
1) Create a Transform with :
- Regex : (\w+)=([\w\d]+)
- Source Key : _raw
- Format : $1::$2
2) Associate that Transform with an Extract pointing to your source.
& you're done ! 🙂
David
Can you post the full event? Splunk will automatically parse out fieds with the '=' sign only. You could easily make a config change to get comma delimited fields though.