Splunk Search

How can I use props and transforms to extract multiline muntivalue event?

nareshinsvu
Builder

Hi experts there,

Trying to extract multivalue output from a multiline json field through props and transforms. How best can I achieve for the below sample data (for my_mvdata field) ?

I can write a regex in pros.conf with \\t delimiter. But only getting the first line. How to use multi add and do it through transforms? 

 

 

 

 

 

{
something: false
somethingelse: true
blah:
blah:
my_mvdata: server1	count1	country1	code1	message1
server2	count1	country1	code1	message2
server3	count1	country1	code1	message3
server4	count1	country1	code1	message4
blah:
blah:
}

 

 

 

 

 

 

Labels (1)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @nareshinsvu,

this seems to be a json format, so use on your props.conf:

INDEXED_EXTRACTIONS = JSON

remember that only for this parameter, it's mandatory to put the props.conf both on Universal Forwarders, Indexers and Search Heads.

Ciao.

Giuseppe

0 Karma

nareshinsvu
Builder

Sure @gcusello , and what else should I put in the conf files to extract that fields as multivalued

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @nareshinsvu,

the above option is useful to extract all the fields as multivalue.

in addition you should add also 

SHOULD_LINEMERGE = true

but in my opinion, the best approach is:

  • take a sample of your logs in a file,
  • ingest it using the GUI guided procedure to choose the correct sourcetype,
  • copy the found sourcetype in all the systems interested to this ingestion.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...