<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to create a search to get the values in table format? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614399#M13990</link>
    <description>&lt;P&gt;My sample logs is:&lt;BR /&gt;2022-09-12 34:45:12.456 info&amp;nbsp; Request uri [/asdff/aii/products] Request patameters [] Request payload [Request body size : : 5678 bytes Request body : : [{\activaterequest\:\ESRTYBBS\*\*, \"addresslines\":[{\"addressLineOrder\":\"NAME\"linevalues\":[\"esmal interger\"]}], \"productsio\":\"IM630\", \"productjourneykey\":\"IM630-p-6789778\",\"lineValues\":[\"sejo guleim ramo versa"]}], \"statusdesc\":\"unknown protocol version. http header [x-aacs-rest-version]. Assuming current version [v1.0]\"}],[{ \number\"4\",\"storePONumber\":\"3456\*}, \"app\",\"message\":\"Action taken when more than 10 points\"}], :[{\"serverstatuscode\":\"400 bad_request\",\"severity\", \"statusdesc\":\"Action taken when more than 10 points\"}], \"number\"6\"]&lt;/P&gt;
&lt;P&gt;My query: index=axcf&amp;nbsp; &amp;nbsp;"Action taken when more than 10 points"&lt;BR /&gt;&lt;BR /&gt;but i want the following values(productsio,&amp;nbsp;addressLineOrder,&amp;nbsp; linevalues,&amp;nbsp;storePONumber, message,&amp;nbsp;serverstatuscode,&amp;nbsp;statusdesc&amp;nbsp; ) in table format.&lt;BR /&gt;&lt;BR /&gt;how can i do this??&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 24 Sep 2022 03:41:47 GMT</pubDate>
    <dc:creator>Vani_26</dc:creator>
    <dc:date>2022-09-24T03:41:47Z</dc:date>
    <item>
      <title>How to create a search to get the values in table format?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614399#M13990</link>
      <description>&lt;P&gt;My sample logs is:&lt;BR /&gt;2022-09-12 34:45:12.456 info&amp;nbsp; Request uri [/asdff/aii/products] Request patameters [] Request payload [Request body size : : 5678 bytes Request body : : [{\activaterequest\:\ESRTYBBS\*\*, \"addresslines\":[{\"addressLineOrder\":\"NAME\"linevalues\":[\"esmal interger\"]}], \"productsio\":\"IM630\", \"productjourneykey\":\"IM630-p-6789778\",\"lineValues\":[\"sejo guleim ramo versa"]}], \"statusdesc\":\"unknown protocol version. http header [x-aacs-rest-version]. Assuming current version [v1.0]\"}],[{ \number\"4\",\"storePONumber\":\"3456\*}, \"app\",\"message\":\"Action taken when more than 10 points\"}], :[{\"serverstatuscode\":\"400 bad_request\",\"severity\", \"statusdesc\":\"Action taken when more than 10 points\"}], \"number\"6\"]&lt;/P&gt;
&lt;P&gt;My query: index=axcf&amp;nbsp; &amp;nbsp;"Action taken when more than 10 points"&lt;BR /&gt;&lt;BR /&gt;but i want the following values(productsio,&amp;nbsp;addressLineOrder,&amp;nbsp; linevalues,&amp;nbsp;storePONumber, message,&amp;nbsp;serverstatuscode,&amp;nbsp;statusdesc&amp;nbsp; ) in table format.&lt;BR /&gt;&lt;BR /&gt;how can i do this??&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Sep 2022 03:41:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614399#M13990</guid>
      <dc:creator>Vani_26</dc:creator>
      <dc:date>2022-09-24T03:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a search to get the values in table format?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614449#M13991</link>
      <description>&lt;P&gt;Please confirm that the sample log is a true representation of your data, because it is a very confusing format with inconsistencies and misspellings.&lt;/P&gt;&lt;P&gt;Assuming it is accurate, please provide the corresponding output you are expecting to see, so we can identify how you log message might be broken down into the field values you are looking for.&lt;/P&gt;&lt;P&gt;Also, another couple of examples might help, so that fixed field names and variable values can more easily be identified.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Sep 2022 09:24:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614449#M13991</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-25T09:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a search to get the values in table format?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614586#M13996</link>
      <description>&lt;P&gt;i want the results in the below format:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;productsio&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;IM630&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;addressLineOrder&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;NAME&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;linevalues&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ejo guleim ramo versa&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;storePONumber&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;3456&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;message&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Action taken when more than 10 points&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;serverstatuscode&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;400 bad_request&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;statusdesc&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Action taken when more than 10 points&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;statusdesc&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN&gt;unknown protocol version. http header [x-aacs-rest-version]. Assuming current version&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [v1.0]&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 16:00:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614586#M13996</guid>
      <dc:creator>Vani_26</dc:creator>
      <dc:date>2022-09-26T16:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a search to get the values in table format?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614698#M13999</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex "\\\\\"productsio\\\\\":\\\\\"(?&amp;lt;productsio&amp;gt;[^\\\\]+)"
| rex "\\\\\"addressLineOrder\\\\\":\\\\\"(?&amp;lt;addressLineOrder&amp;gt;[^\\\\]+)"
| rex "\\\\\"linevalues\\\\\":\[\\\\\"(?&amp;lt;linevalues&amp;gt;[^\\\\]+)"
| rex "\\\\\"storePONumber\\\\\":\\\\\"(?&amp;lt;storePONumber&amp;gt;[^\\\\]+)"
| rex "\\\\\"message\\\\\":\\\\\"(?&amp;lt;message&amp;gt;[^\\\\]+)"
| rex "\\\\\"serverstatuscode\\\\\":\\\\\"(?&amp;lt;serverstatuscode&amp;gt;[^\\\\]+)"
| rex max_match=0 "\\\\\"statusdesc\\\\\":\\\\\"(?&amp;lt;statusdesc&amp;gt;[^\\\\]+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 27 Sep 2022 08:33:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614698#M13999</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-27T08:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a search to get the values in table format?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614822#M14012</link>
      <description>&lt;P&gt;when i am using the below rex&amp;nbsp;getting below error&lt;BR /&gt;Regex:missing terminating ] for character class&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 20:21:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614822#M14012</guid>
      <dc:creator>Vani_26</dc:creator>
      <dc:date>2022-09-27T20:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a search to get the values in table format?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614823#M14013</link>
      <description>&lt;P&gt;What exactly are you using as it looks like a copy/paste/typo?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 20:23:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614823#M14013</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-09-27T20:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a search to get the values in table format?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614829#M14017</link>
      <description>&lt;P&gt;yes i was entering it incorrectly.&lt;/P&gt;&lt;P&gt;thank you,&amp;nbsp; it helped me a lot , its working as expected.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 20:50:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-create-a-search-to-get-the-values-in-table-format/m-p/614829#M14017</guid>
      <dc:creator>Vani_26</dc:creator>
      <dc:date>2022-09-27T20:50:48Z</dc:date>
    </item>
  </channel>
</rss>

