Getting Data In

Using SPATH notation in conf files

danielwysockiar
Explorer

Hi guys,
I need to uto extract fields and values during search time using SPATH notation in props.conf and transforms.conf filles.
I know that there are more convinient ways to do that, but I have to do it this way.

I know how to use spath in SPL, but can someone let me know what the syntax in the .conf file should look like?
I cannot not find it in any docs or answers.
Thank in advance.

0 Karma

sudosplunk
Motivator

Hi,

Are you looking for this?

alt text

0 Karma

danielwysockiar
Explorer

Not exactly, I need search-time extraction defined in .conf files, not indexed extractions.
I can not find how to use spath in props.conf.

0 Karma

sudosplunk
Motivator

KV_MODE is used for search-time field extractions only. These are the values you can set for KV_MODE,

  • none: if you want no field/value extraction to take place.
    • auto: extracts field/value pairs separated by equal signs.
    • auto_escaped: extracts fields/value pairs separated by equal signs and honors \" and \ as escaped sequences within quoted values, e.g field="value with \"nested\" quotes"
    • multi: invokes the multikv search command to expand a tabular event into multiple events.
    • xml : automatically extracts fields from XML data.
    • json: automatically extracts fields from JSON data.
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...