Hi Experts,
I am trying to extract something like below
type=type1,type3
My Data
event1.epochtime=1282182111 type=type1 value=value1 type=type3 value=value3
props.conf
[test]
REPORT-type = mv-type
transform.conf
[mv-type]
REGEX = type=(?type\s+)
MV_ADD = true
Now when I restart after above , I still see only one value in type, so result is type=type1 only . May I know what I am doing wrong ?
Regards
VG
Hi
Can you please try below configuration?
props.conf
[test]
REPORT-type = mv-type
transform.conf
[mv-type]
REGEX = type=(?<type>[^\s+]*)
MV_ADD = true
Thanks
Hi
Can you please try below configuration?
props.conf
[test]
REPORT-type = mv-type
transform.conf
[mv-type]
REGEX = type=(?<type>[^\s+]*)
MV_ADD = true
Thanks
Well it works , I should have seen the comment which was mentioned at the below of the document . So it was the regex problem . Thanks for your response man
I am taking help from below doc and using same example from here
http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Exampleconfigurationsusingfieldtransforms
Use captital S
in your REGEX instead of small case.
REGEX = type=(?<type>\S+)
See the comment from @Daljeanis at the bottom on the documentation.
Thanks mate I should have seen this before ..lolz it works