Hello
I need to create a timechart for the data below based on cpu's available and the utilization of that specific cpu. I have a field for pctSystem so that hasn't been an issue. But I don't have a CPU field which I can use in the timechart. Can anyone please tell me what regex needs to be used to obtain vertical data for CPU
CPU pctUser pctNice pctSystem pctIowait pctIdle
0 51 ? 21 0 28
1 55 ? 19 0 25
all 53 ? 20 0 26
Here's a great reference for you with the multikv command:
http://blogs.splunk.com/2007/08/23/ripping-mulitline-events-at-seach-time/
Previous answer:
http://splunk-base.splunk.com/answers/7352/multikv-field-extraction