<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Default delimiters for key value extraction in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128429#M26372</link>
    <description>&lt;P&gt;Same story with semicolons, pipes, newlines, tabs, ...&lt;/P&gt;</description>
    <pubDate>Wed, 02 Jul 2014 13:33:06 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2014-07-02T13:33:06Z</dc:date>
    <item>
      <title>Default delimiters for key value extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128427#M26370</link>
      <description>&lt;P&gt;I have been sending key value data like the following to Splunk:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;metric1=1.0 metric2=22 metric3="Some string"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have manually wrapped values that may contain spaces in double quotes. I would like to formalize this and write a routine that automatically wraps values in quotes when necessary. To do that &lt;STRONG&gt;I need to know what the default delimiters&lt;/STRONG&gt; are. I could not find a list anywhere.&lt;/P&gt;

&lt;P&gt;Delimiters between key and value: anything else in addition to the equal sign (=)?&lt;/P&gt;

&lt;P&gt;Delimiters between pairs: anything else in addition to the space ( )?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2014 13:23:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128427#M26370</guid>
      <dc:creator>helge</dc:creator>
      <dc:date>2014-07-02T13:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: Default delimiters for key value extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128428#M26371</link>
      <description>&lt;P&gt;Comma is also one of the default delimiters between pairs. If your value contains a comma, it should be in double quotes. See this run anywhere example.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|gentimes start=-1 | eval _raw="First=Example Last=LastName,Email=Example,LastName@gmail.com Email2=\"Example,LastName@gmail.com\"" | table _raw | extract
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should be full list (per my knowledge)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;space
comma
semicolon
pipe
ampersand
tab
new line
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 02 Jul 2014 13:30:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128428#M26371</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-07-02T13:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: Default delimiters for key value extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128429#M26372</link>
      <description>&lt;P&gt;Same story with semicolons, pipes, newlines, tabs, ...&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2014 13:33:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128429#M26372</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-07-02T13:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Default delimiters for key value extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128430#M26373</link>
      <description>&lt;P&gt;I am looking for a full list of delimiters.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2014 13:52:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128430#M26373</guid>
      <dc:creator>helge</dc:creator>
      <dc:date>2014-07-02T13:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: Default delimiters for key value extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128431#M26374</link>
      <description>&lt;P&gt;If you're really looking for something cleanly defined, I would not rely on heuristic key-value detection, but would instead output the event as structured JSON. Splunk can be set to auto extract those, and JSON deals with cases like quoting and embedding delimiters in values.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2014 14:16:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128431#M26374</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2014-07-02T14:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Default delimiters for key value extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128432#M26375</link>
      <description>&lt;P&gt;Do you mean there is no static list of default delimiters? That seems unlikely.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2014 14:31:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128432#M26375</guid>
      <dc:creator>helge</dc:creator>
      <dc:date>2014-07-02T14:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Default delimiters for key value extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128433#M26376</link>
      <description>&lt;P&gt;I mean that if you're looking for a clear definition, you should use something with a clear standard definition, rather than something that is arbitrary, undocumented, and may change from version to version.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jul 2014 14:48:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128433#M26376</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2014-07-02T14:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Default delimiters for key value extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128434#M26377</link>
      <description>&lt;P&gt;This really should be documented by Splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2014 14:16:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128434#M26377</guid>
      <dc:creator>helge</dc:creator>
      <dc:date>2014-07-03T14:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Default delimiters for key value extraction</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128435#M26378</link>
      <description>&lt;P&gt;Interesting  point/approach. Would be nice to have some more details from the Splunk team on this.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jan 2015 18:07:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Default-delimiters-for-key-value-extraction/m-p/128435#M26378</guid>
      <dc:creator>madavies</dc:creator>
      <dc:date>2015-01-09T18:07:25Z</dc:date>
    </item>
  </channel>
</rss>

