<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Extract Command to process single or double quotes in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-Extract-Command-to-process-single-or-double-quotes/m-p/566397#M8492</link>
    <description>&lt;P&gt;Hello Gurus!&lt;/P&gt;&lt;P&gt;I am sure some people may have run in to this.&amp;nbsp; &amp;nbsp;I am using extract command to parse fields from multi line unstructured event, but the data values are encapsulated by single quotes.&lt;/P&gt;&lt;P&gt;Here is the example :&lt;/P&gt;&lt;P&gt;====EVENT 1========&lt;/P&gt;&lt;P&gt;2021-09-08 00:00:00 ABC status - performance event&lt;BR /&gt;&amp;nbsp; &amp;nbsp; name : 'James Bond'&lt;BR /&gt;&amp;nbsp; &amp;nbsp; address : 'USA'&lt;BR /&gt;&amp;nbsp; &amp;nbsp; age : '100'&lt;BR /&gt;&amp;nbsp; &amp;nbsp; occupation : 'spy'&lt;BR /&gt;performance event END&lt;/P&gt;&lt;P&gt;==================&lt;/P&gt;&lt;P&gt;So the the following event, I am using transforms to&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;transforms.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[performance_data]&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;DELIMS = "\r\n", ":"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;So above transforms partially works.&amp;nbsp; The problem is the values has single quote ' encapsulated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Like this&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Field name "name"&amp;nbsp; with value "'James Bond'".&amp;nbsp; &amp;nbsp;single quote included.&amp;nbsp; How can I get rid of the single quote?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Sep 2021 06:06:58 GMT</pubDate>
    <dc:creator>youngc_splunk</dc:creator>
    <dc:date>2021-09-09T06:06:58Z</dc:date>
    <item>
      <title>Splunk Extract Command to process single or double quotes</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-Extract-Command-to-process-single-or-double-quotes/m-p/566397#M8492</link>
      <description>&lt;P&gt;Hello Gurus!&lt;/P&gt;&lt;P&gt;I am sure some people may have run in to this.&amp;nbsp; &amp;nbsp;I am using extract command to parse fields from multi line unstructured event, but the data values are encapsulated by single quotes.&lt;/P&gt;&lt;P&gt;Here is the example :&lt;/P&gt;&lt;P&gt;====EVENT 1========&lt;/P&gt;&lt;P&gt;2021-09-08 00:00:00 ABC status - performance event&lt;BR /&gt;&amp;nbsp; &amp;nbsp; name : 'James Bond'&lt;BR /&gt;&amp;nbsp; &amp;nbsp; address : 'USA'&lt;BR /&gt;&amp;nbsp; &amp;nbsp; age : '100'&lt;BR /&gt;&amp;nbsp; &amp;nbsp; occupation : 'spy'&lt;BR /&gt;performance event END&lt;/P&gt;&lt;P&gt;==================&lt;/P&gt;&lt;P&gt;So the the following event, I am using transforms to&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;transforms.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[performance_data]&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;DELIMS = "\r\n", ":"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;So above transforms partially works.&amp;nbsp; The problem is the values has single quote ' encapsulated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Like this&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Field name "name"&amp;nbsp; with value "'James Bond'".&amp;nbsp; &amp;nbsp;single quote included.&amp;nbsp; How can I get rid of the single quote?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Sep 2021 06:06:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-Extract-Command-to-process-single-or-double-quotes/m-p/566397#M8492</guid>
      <dc:creator>youngc_splunk</dc:creator>
      <dc:date>2021-09-09T06:06:58Z</dc:date>
    </item>
  </channel>
</rss>

