Hello all,
I am trying to get the value of a field from an event in Splunk. The event looks like follows:
message="abtest platform=\"Target\", [testName=\"test1\",testId=\"253041,\",experience=\"lefNavigation\"]"
For the above event, how could I do a count by "testName", "testId" and "experience"? Currently, when I do count by on the message source, value for the above fields come as a backslash() .
Thanks a LOT in advance!
Hi newsplnkr,
did you tried with this regex?
message\=\"abtest platform\=\\\"(?P<abtest_platform>[^\\]*)\\\",\s*\[testName\=\\\"(?P<testName>[^\\]*)\\\",testId\=\\\"(?P<testId>[^,]*),\\\",experience\=\\\"(?P<experience>[^\\]*)
you can test it at https://regex101.com/r/g5u6kU/1
Bye.
Giuseppe
In props.conf you should specify KV_MODE = auto_escaped for a sourcetype that has values like this