Hi all,
I am using DB connect to retrieve a list of user accounts from a database.
The extract is running as expected, but the username sometimes contain commas:
Username=Lastname,Firstnam
e
This will cause Splunk to read only the first part of the user name to the field "Username".
Is there a way to place the results of my query in quotes to achieve this:
Username="Lastname,Firstname"
?
Thanks
Norbert
Have you tried the multi-line key-value output format?
If all else fails you should be able to specify a manual template as the output format, and include quotes explicitly:
... Username="$user_column$" ...
That may be tedious for a large number of columns of course.
Great 🙂
I have converted the comment to an answer so you can mark it as solved.
Cool, I have used the template, now I have exactly what I was looking for.
Greetings to the north! 🙂
Have you tried the multi-line key-value output format?
If all else fails you should be able to specify a manual template as the output format, and include quotes explicitly:
... Username="$user_column$" ...
That may be tedious for a large number of columns of course.