<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: matching fixed width fields or fields with spaces from scripted input in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/matching-fixed-width-fields-or-fields-with-spaces-from-scripted/m-p/53171#M12925</link>
    <description>&lt;P&gt;If you were running this input script on a Linux system, you could use awk to "normalize" the format of the  &lt;CODE&gt;iisweb.vbs /querv&lt;/CODE&gt; output into something that multikv would like better, before you ever input the data into Splunk.&lt;/P&gt;

&lt;P&gt;But you can do the same thing with Splunk, too.  Assuming that your sourcetype is &lt;CODE&gt;iis-querv&lt;/CODE&gt;, put the following in your props.conf (on the indexer, not the forwarder)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[iis-querv]
SEDCMD-sed1 = s/(.*)Site Name \(Metabase Path)(.*)/\1SiteName (MetabasePath)\2/g
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should remove the spaces in the heading names.  I don't know that this will be enough for multikv to work, as there also appears to be some variations in the rows of the table.  But try it.  &lt;/P&gt;

&lt;P&gt;This is another application of the concepts in the documentation under &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3/Data/Anonymizedatausingconfigurationfiles"&gt;Anonymize data&lt;/A&gt;.  HTH!&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jan 2012 08:32:36 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2012-01-18T08:32:36Z</dc:date>
    <item>
      <title>matching fixed width fields or fields with spaces from scripted input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/matching-fixed-width-fields-or-fields-with-spaces-from-scripted/m-p/53170#M12924</link>
      <description>&lt;P&gt;I'm attempting to pull in data from &lt;CODE&gt;iisweb.vbs /querv&lt;/CODE&gt; ia a scripted input.  On Windows this will show a table of the status of each IIS site including a mapping from the crazy W3SVC directory name and the actual site.  Example output that the scripted input is sticking into my index is something like&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\WINDOWS\system32&amp;gt;C:\WINDOWS\System32\iisweb.vbs /query 
Microsoft (R) Windows Script Host Version 5.6
Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.

Connecting to server ...Done.
Site Name (Metabase Path)                     Status  IP              Port  Host
==============================================================================
foo.bar.com (W3SVC/12345678)                  STARTED 1.2.3.4         80    foo.bar.com
fiz.bar.com (W3SVC/23456789)                  STOPPED 2.3.4.5         81    fiz.bar.com
test.bar.com (W3SVC/34567890)                 STARTED 3.4.5.6         90    N/A
Blaz Redirect to SSL (W3SVC/231245678)        STARTED 1.2.2.1         95    N/A
Pish-Posh (W3SVC/901237894)                   STARTED 3.7.2.1         98    N/A
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and so on.  I would like to be able to extract this as multi-valued set of fields.   I'd like to do that as part of my props.conf/transforms.conf search time extractions, but just experimenting using multikv from the command line to see what I might get isn't giving me what I want.  It appears that it's because of the items in "Site Name" that can have spaces in them and multikv does not like spaces.&lt;/P&gt;

&lt;P&gt;Maybe this is more than multikv can handle (which is fine), but can I manage to do what I want with props.conf/transforms.conf?   The regex for each line would seem fairly straightforward, but it's not clear to me how to define that via props.conf/transforms.conf for search time extraction.&lt;/P&gt;

&lt;P&gt;Any help and/or pointers are greatly appreciated.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2012 04:07:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/matching-fixed-width-fields-or-fields-with-spaces-from-scripted/m-p/53170#M12924</guid>
      <dc:creator>mfrost8</dc:creator>
      <dc:date>2012-01-18T04:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: matching fixed width fields or fields with spaces from scripted input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/matching-fixed-width-fields-or-fields-with-spaces-from-scripted/m-p/53171#M12925</link>
      <description>&lt;P&gt;If you were running this input script on a Linux system, you could use awk to "normalize" the format of the  &lt;CODE&gt;iisweb.vbs /querv&lt;/CODE&gt; output into something that multikv would like better, before you ever input the data into Splunk.&lt;/P&gt;

&lt;P&gt;But you can do the same thing with Splunk, too.  Assuming that your sourcetype is &lt;CODE&gt;iis-querv&lt;/CODE&gt;, put the following in your props.conf (on the indexer, not the forwarder)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[iis-querv]
SEDCMD-sed1 = s/(.*)Site Name \(Metabase Path)(.*)/\1SiteName (MetabasePath)\2/g
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should remove the spaces in the heading names.  I don't know that this will be enough for multikv to work, as there also appears to be some variations in the rows of the table.  But try it.  &lt;/P&gt;

&lt;P&gt;This is another application of the concepts in the documentation under &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3/Data/Anonymizedatausingconfigurationfiles"&gt;Anonymize data&lt;/A&gt;.  HTH!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2012 08:32:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/matching-fixed-width-fields-or-fields-with-spaces-from-scripted/m-p/53171#M12925</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-01-18T08:32:36Z</dc:date>
    </item>
  </channel>
</rss>

