Hi,
I am new in splunk and i want to save the value in fields before and after =
for example events look like below
rollnumber=34556
class=12
I want to return rollnumber and class in first field and the number after = in second field.
base search | rex max_match=15 field=_raw "(?P)="
this doesnt work, both values are coming as space.
Your regex seems to be incomplete, could you try:
| rex max_match=15 field=_raw "(?P<field1>\w+)\=(?P<field2>\w+)"
Your regex seems to be incomplete, could you try:
| rex max_match=15 field=_raw "(?P<field1>\w+)\=(?P<field2>\w+)"