<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can not extract value with whitespace at index time in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-extract-value-with-whitespace-at-index-time/m-p/602436#M104901</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a not ideal log, looking like this, for example:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;"field1=value1"&amp;nbsp; "field2=val ue 2" "field3=value3"&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I want to exlude the key-value pairs at index time.&lt;/P&gt;&lt;P&gt;Combinations like the first kv-pair is not problem. The second value however is a problem. With my extraction I can only get the "val" part, and the extraction stops at the whitespace.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My rule in transforms.conf looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[example]
REGEX = (?&amp;lt;_KEY_1&amp;gt;([^=\"]+)=(?&amp;lt;_VAL_1&amp;gt;([^=\"]+)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To clarify, my results in splunk are looking like this:&lt;/P&gt;&lt;P&gt;field1 = value1&lt;/P&gt;&lt;P&gt;field2 = val&lt;/P&gt;&lt;P&gt;field3 = value3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure what I am missing.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jun 2022 17:01:17 GMT</pubDate>
    <dc:creator>sebastian_pribn</dc:creator>
    <dc:date>2022-06-20T17:01:17Z</dc:date>
    <item>
      <title>Can not extract value with whitespace at index time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-extract-value-with-whitespace-at-index-time/m-p/602436#M104901</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a not ideal log, looking like this, for example:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;"field1=value1"&amp;nbsp; "field2=val ue 2" "field3=value3"&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I want to exlude the key-value pairs at index time.&lt;/P&gt;&lt;P&gt;Combinations like the first kv-pair is not problem. The second value however is a problem. With my extraction I can only get the "val" part, and the extraction stops at the whitespace.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My rule in transforms.conf looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[example]
REGEX = (?&amp;lt;_KEY_1&amp;gt;([^=\"]+)=(?&amp;lt;_VAL_1&amp;gt;([^=\"]+)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To clarify, my results in splunk are looking like this:&lt;/P&gt;&lt;P&gt;field1 = value1&lt;/P&gt;&lt;P&gt;field2 = val&lt;/P&gt;&lt;P&gt;field3 = value3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure what I am missing.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 17:01:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-not-extract-value-with-whitespace-at-index-time/m-p/602436#M104901</guid>
      <dc:creator>sebastian_pribn</dc:creator>
      <dc:date>2022-06-20T17:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can not extract value with whitespace at index time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-extract-value-with-whitespace-at-index-time/m-p/602455#M104905</link>
      <description>&lt;P&gt;You have the right regex, but with a slightly muddled syntax (too many left parens).&amp;nbsp; Try this alternative:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[example]
REGEX = ([^=\"]+)=([^=\"]+)
FORMAT = $1::$2&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 18:26:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-not-extract-value-with-whitespace-at-index-time/m-p/602455#M104905</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-06-20T18:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can not extract value with whitespace at index time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-extract-value-with-whitespace-at-index-time/m-p/602485#M104906</link>
      <description>&lt;P&gt;If the key-value pairs are enclosed in parentheses I'd anchor the regex in parentheses as well.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 20:43:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-not-extract-value-with-whitespace-at-index-time/m-p/602485#M104906</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-06-20T20:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can not extract value with whitespace at index time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-extract-value-with-whitespace-at-index-time/m-p/602555#M104910</link>
      <description>&lt;P&gt;Oh, you are right. I had run so many tests yesterday that it was getting a little confusing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried both variants, with the same regex:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[example]
REGEX = (?&amp;lt;_KEY_1&amp;gt;([^=\"]+))=(?&amp;lt;_VAL_1&amp;gt;([^=\"]+))&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[example]
REGEX = ([^=\"]+)=([^=\"]+)
FORMAT = $1::$2&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I am only getting the value to the first whitespace.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;"key=val ue"&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;will result in&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;key=val&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;with both variants.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tested all changes in &lt;FONT face="courier new,courier"&gt;props.conf&lt;/FONT&gt; / &lt;FONT face="courier new,courier"&gt;transforms.conf&lt;/FONT&gt; under &lt;FONT face="courier new,courier"&gt;etc/system/local&lt;/FONT&gt; to ensure, that there is no other setting that is overwriting my tests.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe I should also mention that these value are embedded in some kind of pseudo json format. I am, however, not using indexed extractions.&lt;/P&gt;&lt;P&gt;The events are looking something like this:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;{"severity":"info","time":"123456789","message":"key1=value1" "key2=val ue 2"}&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 07:45:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-not-extract-value-with-whitespace-at-index-time/m-p/602555#M104910</guid>
      <dc:creator>sebastian_pribn</dc:creator>
      <dc:date>2022-06-21T07:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can not extract value with whitespace at index time</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-not-extract-value-with-whitespace-at-index-time/m-p/602619#M104915</link>
      <description>&lt;P&gt;The regex should work.&amp;nbsp; It works in regex101.com.&amp;nbsp; See&amp;nbsp;&lt;A href="https://regex101.com/r/ZHCFQp/1" target="_blank"&gt;https://regex101.com/r/ZHCFQp/1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 13:33:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-not-extract-value-with-whitespace-at-index-time/m-p/602619#M104915</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-06-21T13:33:52Z</dc:date>
    </item>
  </channel>
</rss>

