<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to extract fields from database column using sql query on splunk db connect application. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-fields-from-database-column-using-sql-query-on/m-p/536248#M89900</link>
    <description>&lt;P&gt;extract command in Splunk may help..&lt;/P&gt;&lt;P&gt;Sample query:&lt;/P&gt;&lt;P&gt;|makeresults | eval _raw=" Status&lt;BR /&gt;login failed...\nhost=xyz |\nip=0.0.0.0&lt;BR /&gt;login successful&lt;BR /&gt;host=xyz |\n ip=0.0.0.0 |" | multikv forceheader=1 | eval Status=split(Status,"\n") | eval temp=_raw,_raw=Status | extract | rename temp as _raw&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jan 2021 18:07:39 GMT</pubDate>
    <dc:creator>saravanan90</dc:creator>
    <dc:date>2021-01-18T18:07:39Z</dc:date>
    <item>
      <title>How to extract fields from database column using sql query on splunk db connect application.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-fields-from-database-column-using-sql-query-on/m-p/536246#M89899</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I kindly request your help to get fields extracted from database column. I'm working on splunk db-connect app. Can anyone please provide me sample sql query to extract subfields from status field?&lt;/P&gt;&lt;P&gt;For e.g. I would need something like msg=login failed, host and ip fields to be extracted from below unique database records.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sample Database output with unique records from splunk db-connect app:&lt;/P&gt;&lt;P&gt;&amp;nbsp;Date&amp;nbsp; &amp;nbsp;User&amp;nbsp; Input&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Status&lt;/P&gt;&lt;P&gt;&amp;nbsp; xxx&amp;nbsp; &amp;nbsp; &amp;nbsp;abc&amp;nbsp; &amp;nbsp; &amp;nbsp; 123&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; login failed...&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; host=xyz |&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ip=0.0.0.0 |&lt;/P&gt;&lt;P&gt;&amp;nbsp;yyy&amp;nbsp; &amp;nbsp; &amp;nbsp; xyz&amp;nbsp; &amp;nbsp; &amp;nbsp; 456&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;login successful&lt;/P&gt;&lt;P&gt;&amp;nbsp;zzz&amp;nbsp; &amp;nbsp; &amp;nbsp;pqr&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;789&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;host=xyz |&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ip=0.0.0.0 |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate your help!!&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 17:44:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-fields-from-database-column-using-sql-query-on/m-p/536246#M89899</guid>
      <dc:creator>firefox95</dc:creator>
      <dc:date>2021-01-18T17:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract fields from database column using sql query on splunk db connect application.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-fields-from-database-column-using-sql-query-on/m-p/536248#M89900</link>
      <description>&lt;P&gt;extract command in Splunk may help..&lt;/P&gt;&lt;P&gt;Sample query:&lt;/P&gt;&lt;P&gt;|makeresults | eval _raw=" Status&lt;BR /&gt;login failed...\nhost=xyz |\nip=0.0.0.0&lt;BR /&gt;login successful&lt;BR /&gt;host=xyz |\n ip=0.0.0.0 |" | multikv forceheader=1 | eval Status=split(Status,"\n") | eval temp=_raw,_raw=Status | extract | rename temp as _raw&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 18:07:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-fields-from-database-column-using-sql-query-on/m-p/536248#M89900</guid>
      <dc:creator>saravanan90</dc:creator>
      <dc:date>2021-01-18T18:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract fields from database column using sql query on splunk db connect application.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-fields-from-database-column-using-sql-query-on/m-p/536252#M89901</link>
      <description>&lt;P&gt;You should contact a DBA for the database in question for help writing a SQL query for that database.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 19:03:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-fields-from-database-column-using-sql-query-on/m-p/536252#M89901</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-18T19:03:03Z</dc:date>
    </item>
  </channel>
</rss>

