Getting Data In

passing of events field with spaces

swetar
New Member

Hi,
I wanted to display Message in message field value. I wanted to do the set up in prof.conf. Can anyone please help me in this?
MESSAGE=PPQR14142 PghZDxfscbn :ascasc12 are the code
MESSAGE=JKhjagsdh QSL:ghjgfhs :XXXXX101 are the next code

Thanks

Tags (2)
0 Karma

jplumsdaine22
Influencer

The best way to handle this is to have double quotes in your event. IE make it something like

MESSAGE="PPQR14142 PghZDxfscbn :ascasc12"

Otherwise build a regex extraction with the field extractor: http://docs.splunk.com/Documentation/Splunk/7.1.2/Knowledge/ExtractfieldsinteractivelywithIFX

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...