Thanks for your input DalJeanis.
I've tried to follow the steps but somehow it didn't seperate the fields into their own lines and i can't draw a graph with it.
Here's the search string I used
sourcetype="vpn-stats" "show clock" | rex field=_raw "Username : (?<VPNUser>\w+)" max_match=0 | rex field=_raw "Bytes Tx : (?<VPNTX>\w+)" max_match=0 | eval fields = mvzip(VPNUser,VPNTX) | mvexpand fields | eval fields = mvzip(VPNUser,VPNTX) | table _time fields
The result is like following
_time fields
5/15/17 2:57 PM User1,641674831
User2,92081181
User3,52384414
…
5/15/17 2:57 PM User1,641674800
User2,92081100
User3,52384400
…
5/15/17 2:57 PM …
Maybe my mvexpand was wrong?
... View more