<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I extract multiple fields? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638741#M109070</link>
    <description>&lt;P&gt;I have a log event and I want to extract like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24781iEE1E3A3E1BDF57A5/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I want to show it line the red line. How ever it just recive the first line in event. how to show all the blue line?&lt;/P&gt;
&lt;P&gt;Thank you for your help.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Apr 2023 16:43:51 GMT</pubDate>
    <dc:creator>jacknguyen</dc:creator>
    <dc:date>2023-04-05T16:43:51Z</dc:date>
    <item>
      <title>How can I extract multiple fields?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638741#M109070</link>
      <description>&lt;P&gt;I have a log event and I want to extract like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24781iEE1E3A3E1BDF57A5/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I want to show it line the red line. How ever it just recive the first line in event. how to show all the blue line?&lt;/P&gt;
&lt;P&gt;Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 16:43:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638741#M109070</guid>
      <dc:creator>jacknguyen</dc:creator>
      <dc:date>2023-04-05T16:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Extrac Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638742#M109071</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249232"&gt;@jacknguyen&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It is easier to help if you copy and paste the whole event as text - place inside a preformatted style, or code sample &amp;lt;/&amp;gt; helps too.&lt;BR /&gt;&lt;BR /&gt;Screen shots like this, with big multi-line events make it far harder to help and get some SPL code working.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 02:53:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638742#M109071</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-04-05T02:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: Extrac Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638743#M109072</link>
      <description>&lt;P&gt;this is event:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;lt;/&amp;gt;TITLE&lt;/SPAN&gt;&lt;SPAN&gt;,OpenVPN 2.4.11 x86_64-redhat-linux-gnu [Fedora EPEL patched] [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Apr 21 2021 TIME,Wed Apr 5 08:58:23 2023,1680659903 HEADER,CLIENT_LIST,Common Name,Real Address,Virtual Address,Virtual IPv6 Address,Bytes Received,Bytes Sent,Connected Since,Connected Since (time_t),Username,Client ID,Peer ID CLIENT_LIST,&lt;/SPAN&gt;&lt;SPAN class=""&gt;jack_nguyen&lt;/SPAN&gt;&lt;SPAN&gt;,116.100.47.155:1130,&lt;/SPAN&gt;&lt;SPAN class=""&gt;10.10.0.25&lt;/SPAN&gt;&lt;SPAN&gt;,,2293690,17795968,&lt;/SPAN&gt;&lt;SPAN class=""&gt;Wed Apr 5 08:38:22 2023&lt;/SPAN&gt;&lt;SPAN&gt;,1680658702,jack_nguyen,201,2 CLIENT_LIST,kane_vu,116.100.47.155:1135,10.10.0.35,,807236,269755,Wed Apr 5 08:50:46 2023,1680659446,kane_vu,202,3 CLIENT_LIST,wanki_trinh,116.100.47.155:1194,10.10.0.21,,891114,9413845,Wed Apr 5 08:34:28 2023,1680658468,wanki_trinh,200,1 CLIENT_LIST,torin_huynh,116.110.42.16:62901,10.10.0.32,,2798473,5631112,Wed Apr 5 08:26:47 2023,1680658007,torin_huynh,199,0 CLIENT_LIST,william_vo,116.100.47.155:1138,10.10.0.22,,621296,10725869,Wed Apr 5 08:55:22 2023,1680659722,william_vo,203,4 HEADER,ROUTING_TABLE,Virtual Address,Common Name,Real Address,Last Ref,Last Ref (time_t) ROUTING_TABLE,10.10.0.22,william_vo,116.100.47.155:1138,Wed Apr 5 08:58:22 2023,1680659902 ROUTING_TABLE,10.10.0.25,jack_nguyen,116.100.47.155:1130,Wed Apr 5 08:58:22 2023,1680659902 ROUTING_TABLE,10.10.0.21,wanki_trinh,116.100.47.155:1194,Wed Apr 5 08:58:17 2023,1680659897 ROUTING_TABLE,10.10.0.35,kane_vu,116.100.47.155:1135,Wed Apr 5 08:58:22 2023,1680659902 ROUTING_TABLE,10.10.0.32,torin_huynh,116.110.42.16:62901,Wed Apr 5 08:58:22 2023,1680659902 GLOBAL_STATS,Max bcast/mcast queue length,6 END&amp;lt;\&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 03:00:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638743#M109072</guid>
      <dc:creator>jacknguyen</dc:creator>
      <dc:date>2023-04-05T03:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: Extrac Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638745#M109073</link>
      <description>&lt;P&gt;Sorry, I could have been clearer, the &amp;lt;/&amp;gt; is an icon in the editor where you can add content so that the output does not get modified.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="yeahnah_0-1680663909520.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24782iA64D5444D7B26F28/image-size/medium?v=v2&amp;amp;px=400" role="button" title="yeahnah_0-1680663909520.png" alt="yeahnah_0-1680663909520.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please try adding again&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 03:06:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638745#M109073</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-04-05T03:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Extrac Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638746#M109074</link>
      <description>&lt;LI-CODE lang="markup"&gt;TITLE,OpenVPN 2.4.11 x86_64-redhat-linux-gnu [Fedora EPEL patched] [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Apr 21 2021
TIME,Tue Apr  4 15:57:03 2023,1680598623
HEADER,CLIENT_LIST,Common Name,Real Address,Virtual Address,Virtual IPv6 Address,Bytes Received,Bytes Sent,Connected Since,Connected Since (time_t),Username,Client ID,Peer ID
CLIENT_LIST,louis_tran,116.100.47.155:1044,10.10.0.20,,13285791,65784195,Tue Apr  4 09:21:41 2023,1680574901,louis_tran,181,1
CLIENT_LIST,wanki_trinh,116.100.47.155:1194,10.10.0.21,,13753119,165936845,Tue Apr  4 09:15:02 2023,1680574502,wanki_trinh,180,0
CLIENT_LIST,william_nguyen,116.100.47.155:1107,10.10.0.46,,2458734,17228162,Tue Apr  4 13:53:19 2023,1680591199,william_nguyen,186,4
CLIENT_LIST,kane_vu,116.100.47.155:1106,10.10.0.35,,8842662,20247670,Tue Apr  4 13:44:11 2023,1680590651,kane_vu,185,3
CLIENT_LIST,peter_nguyen,116.100.47.155:1118,10.10.0.12,,14031959,28603186,Tue Apr  4 15:16:46 2023,1680596206,peter_nguyen,190,5
CLIENT_LIST,jack_nguyen,116.100.47.155:1049,10.10.0.25,,31338513,125792327,Tue Apr  4 09:32:59 2023,1680575579,jack_nguyen,182,2
HEADER,ROUTING_TABLE,Virtual Address,Common Name,Real Address,Last Ref,Last Ref (time_t)
ROUTING_TABLE,10.10.0.25,jack_nguyen,116.100.47.155:1049,Tue Apr  4 15:57:01 2023,1680598621
ROUTING_TABLE,10.10.0.21,wanki_trinh,116.100.47.155:1194,Tue Apr  4 15:56:44 2023,1680598604
ROUTING_TABLE,10.10.0.35,kane_vu,116.100.47.155:1106,Tue Apr  4 15:57:02 2023,1680598622
ROUTING_TABLE,10.10.0.20,louis_tran,116.100.47.155:1044,Tue Apr  4 15:56:59 2023,1680598619
ROUTING_TABLE,10.10.0.46,william_nguyen,116.100.47.155:1107,Tue Apr  4 15:57:02 2023,1680598622
ROUTING_TABLE,10.10.0.12,peter_nguyen,116.100.47.155:1118,Tue Apr  4 15:57:01 2023,1680598621
GLOBAL_STATS,Max bcast/mcast queue length,6
END&lt;/LI-CODE&gt;&lt;P&gt;oh sorry my fault. there is&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 03:08:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638746#M109074</guid>
      <dc:creator>jacknguyen</dc:creator>
      <dc:date>2023-04-05T03:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Extrac Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638747#M109075</link>
      <description>&lt;P&gt;Thanks, that helps a lot.&lt;BR /&gt;&lt;BR /&gt;It's an interesting data set, multi-line with different CSV headers in the one event.&lt;BR /&gt;&lt;BR /&gt;The following is a method that should meet your use case&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... your search ...
| rex field=_raw "^(?:.+?[\n\r]){2}HEADER,(?&amp;lt;_raw&amp;gt;(.+[\n\r])+)HEADER"
| multikv forceheader=1
| table Common_Name Virtual_Address Connected_Since&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It pulls out (rex) the CSV section you're interested in and then uses the multikv command to extract the data as single line events.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;You can rename the output fields if you like too.&lt;BR /&gt;&lt;BR /&gt;Here's my run anywhere search I used to test the above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval event="TITLE,OpenVPN 2.4.11 x86_64-redhat-linux-gnu [Fedora EPEL patched] [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Apr 21 2021
TIME,Tue Apr  4 15:57:03 2023,1680598623
HEADER,CLIENT_LIST,Common Name,Real Address,Virtual Address,Virtual IPv6 Address,Bytes Received,Bytes Sent,Connected Since,Connected Since (time_t),Username,Client ID,Peer ID
CLIENT_LIST,louis_tran,116.100.47.155:1044,10.10.0.20,,13285791,65784195,Tue Apr  4 09:21:41 2023,1680574901,louis_tran,181,1
CLIENT_LIST,wanki_trinh,116.100.47.155:1194,10.10.0.21,,13753119,165936845,Tue Apr  4 09:15:02 2023,1680574502,wanki_trinh,180,0
CLIENT_LIST,william_nguyen,116.100.47.155:1107,10.10.0.46,,2458734,17228162,Tue Apr  4 13:53:19 2023,1680591199,william_nguyen,186,4
CLIENT_LIST,kane_vu,116.100.47.155:1106,10.10.0.35,,8842662,20247670,Tue Apr  4 13:44:11 2023,1680590651,kane_vu,185,3
CLIENT_LIST,peter_nguyen,116.100.47.155:1118,10.10.0.12,,14031959,28603186,Tue Apr  4 15:16:46 2023,1680596206,peter_nguyen,190,5
CLIENT_LIST,jack_nguyen,116.100.47.155:1049,10.10.0.25,,31338513,125792327,Tue Apr  4 09:32:59 2023,1680575579,jack_nguyen,182,2
HEADER,ROUTING_TABLE,Virtual Address,Common Name,Real Address,Last Ref,Last Ref (time_t)
ROUTING_TABLE,10.10.0.25,jack_nguyen,116.100.47.155:1049,Tue Apr  4 15:57:01 2023,1680598621
ROUTING_TABLE,10.10.0.21,wanki_trinh,116.100.47.155:1194,Tue Apr  4 15:56:44 2023,1680598604
ROUTING_TABLE,10.10.0.35,kane_vu,116.100.47.155:1106,Tue Apr  4 15:57:02 2023,1680598622
ROUTING_TABLE,10.10.0.20,louis_tran,116.100.47.155:1044,Tue Apr  4 15:56:59 2023,1680598619
ROUTING_TABLE,10.10.0.46,william_nguyen,116.100.47.155:1107,Tue Apr  4 15:57:02 2023,1680598622
ROUTING_TABLE,10.10.0.12,peter_nguyen,116.100.47.155:1118,Tue Apr  4 15:57:01 2023,1680598621
GLOBAL_STATS,Max bcast/mcast queue length,6
END"
  ``` above just creates the dummy events ```
| rex field=event "^(?:.+?[\n\r]){2}HEADER,(?&amp;lt;_raw&amp;gt;(.+[\n\r])+)HEADER"
| multikv forceheader=1
| table Common_Name Virtual_Address Connected_Since&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 03:34:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/638747#M109075</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-04-05T03:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: Extrac Fields</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/639441#M109182</link>
      <description>&lt;P&gt;thank you for your help. its work&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 03:25:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-extract-multiple-fields/m-p/639441#M109182</guid>
      <dc:creator>jacknguyen</dc:creator>
      <dc:date>2023-04-11T03:25:47Z</dc:date>
    </item>
  </channel>
</rss>

