Hi Guys ,
I would like to extract the values that are highlited below into different fields. Can you please help me with the best way other than using the .conf files.
PS: the follwoing text getting logged as single event in splunk by default.
\x00\x00jS\x00\x00\x00\x00\x00\x00**2019-03-07**\x00\x00\x00**hoganids** \x00\x00\x00**sanitized**
\x00\x00\x00**dda_masterb**\x00\x00\x00**/apps/dat/aasconap/prod/mfs/mfs_8way/cnapp/cnapp_src/cnapp_src_hoganids/main/./dda_master_PG54.dat&**\x00\x00\x00**consumer_hoganids_sanitized.dda_master**\x00\x00\x00**amf_5_cf.dat2019-03-08 03:11:32.9940612019-03-08 03:16:42.693043=**\x00\x00\x00**warning - 35% data volume threshold reached, expected 2639757**\x00\x**00jS**\x00\x00\x00\x00\x00\x00**2019-03-07**\x00\x00\x00**hoganids** \x00\x00\x00**sanitized**
\x00\x00\x00**dda_masterb**\x00\x00\x00**/apps/dat/aasconap/prod/mfs/mfs_8way/cnapp/cnapp_src/cnapp_src_hoganids/main/./dda_master_PG54.dat**&\x00\x00\x00**consumer_hoganids_sanitized.dda_master**\x00\x00\x00**amf_5_cf.dat2019-03-08 03:11:32.9940612019-03-08 03:16:42.693043**\x00\x00\x00**success**\x00\x00**jS**\x00\x00\x00\x00\x00\x00**2019-03-07**\x00\x00\x00**hoganids** \x00\x00\x00**conformed**
\x00\x00\x00**dep_dmnd_acctb**\x00\x00\x00**/apps/dat/aasconap/prod/mfs/mfs_8way/cnapp/cnapp_src/cnapp_src_hoganids/main/./dda_master_PG54.dat1**\x00\x00\x00**consumer_servicingaccount_conformed.dep_dmnd_acct**\x00\x00\x00**amf_5_cf.dat2019-03-08 03:11:32.9940612019-03-08 03:16:42.693043=**\x00\x00\x00**warning - 35% data volume threshold reached, expected 2639757**
@jkat54 @vnravikumar
As @FrankVI mentioned that it looks like encoding issue, if you know what type of encoding or character set is present in your file in that case you can set CHARSET
parameter in props.conf, have a look at document https://docs.splunk.com/Documentation/Splunk/7.2.4/Data/Configurecharactersetencoding
Splunk software attempts to apply UTF-8 encoding to your sources by default. If a source does not use UTF-8 encoding or is a non-ASCII file, Splunk software tries to convert data from the source to UTF-8 encoding unless you specify a character set to use by setting the CHARSET key in props.conf.
Looks like you have some encoding issues, I'd suggest getting that fixed first (probably the encoding used to ingest this data does not match the actual encoding of the data).
And it is also completely unclear to me what parts you actually want to extract, can you please mark that more clearly?
What fields do you want extracted? There is nothing "highlighted" in your question.
Do you want to extract them at index time or search time?
Please find the updated event here
\x00\x00jS\x00\x00\x00\x00\x00\x00**2019-03-07**\x00\x00\x00**hoganids** \x00\x00\x00**sanitized**
\x00\x00\x00**dda_masterb**\x00\x00\x00**/apps/dat/aasconap/prod/mfs/mfs_8way/cnapp/cnapp_src/cnapp_src_hoganids/main/./dda_master_PG54.dat&**\x00\x00\x00**consumer_hoganids_sanitized.dda_master \x00\x00\x00amf_5_cf.dat2019-03-08 03:11:32.9940612019-03-08 03:16:42.693043=**\x00\x00\x00**warning - 35% data volume threshold reached, expected 2639757**\x00\x00jS\x00\x00\x00\x00\x00\x00**2019-03-07**\x00\x00\x00**hoganids** \x00\x00\x00**sanitized**
\x00\x00\x00**dda_masterb\x00\x00\x00/apps/dat/aasconap/prod/mfs/mfs_8way/cnapp/cnapp_src/cnapp_src_hoganids/main/./dda_master_PG54.dat&**\x00\x00\x00**consumer_hoganids_sanitized.dda_master \x00\x00\x00amf_5_cf.dat2019-03-08 03:11:32.9940612019-03-08 03:16:42.693043**\x00\x00\x00**success**