<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic need to help to extract few fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495614#M138155</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;I have the following as raw event&lt;/P&gt;

&lt;P&gt;INFO : [0:HLog][20200507 12:25:25.739 -0400] [CFarmdHealth.java:538] +1{"garbage_collec: {"total_collections_time":16539,"last_minute_collections":5,"last_minute_collections_time.:38,"totalcollections":2313},"current_state":&lt;BR /&gt;
{"event_processing_metric":0.6647058823529413,&lt;STRONG&gt;"message_queues":{"maintenanceWindowManager":"0/-","Hibernate":"0/-","Default Cookbook":"0/-","Alert Workflows":"0/-",.StatCollector":"0/-","bus_thread_pool":"0/-","Event Workflows":"0/-","SituationMgr":"0/-","SituationRootCause":"0/-","Remedy":.0/-","AlertBuilder":"0/-","TeamsMgr":"0/-","xMatters":"0/-","Housekeeper":"0/-","Situation Workflows":"0/-","Indexer":"0/-","MaintManager":"0/-","NCAlertBuilder":"0/-","SMCEnricher":"0/-","xmattersINS":"0/-",.AlertRulesEngine":"0/-"},"in_memory_entropies.:781,"cookbook_resolu _queue":0,"active_async_tasks_count":0},"interval_totals":{"created events":621,"created_external_situations.:0,"created_situations":0&lt;/STRONG&gt;,"&lt;STRONG&gt;messages_processed": {"maintenanceWindowManager":621,"Default Cookbook":548,"Alert Workflows":621,"StatCollector":0,"Event Workflows":597,"situationRootCause":0,"SituationMgr":0,"AlertBuilder":597,"TeamsMgr":0,"xMatters":0,"Indexer":666,"Situation Workflows":0,"maintManager":666,"SMCEnricher":621,NCAlertBuilder":597,xMattersINS":0,"AlertRulesEngine":548},"alerts_added_to situations":0,"situation_db_update_failure":0},JVM_memor]&lt;/STRONG&gt; {"heap_used":314179032,"heap_committed":488636416,"heap_init":195035136,"nonheap_committed":290652160,"heap_max":3107979264,"nonheap_init":7667712,"nonheap_used":263293720,"nonheap_max" 1},"totals":{"created_events":178016,"created_external_situations":0,"created_situations":0,"alerts_added_to situations":0,"situation_db_update_failure":0}}1+&lt;/P&gt;

&lt;P&gt;Now i have to build the kind of tables in the attachment out of above highlighted text in the event,  Can you please help&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/290686-s.png" alt="alt text" /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 05:23:20 GMT</pubDate>
    <dc:creator>pench2k19</dc:creator>
    <dc:date>2020-09-30T05:23:20Z</dc:date>
    <item>
      <title>need to help to extract few fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495614#M138155</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;I have the following as raw event&lt;/P&gt;

&lt;P&gt;INFO : [0:HLog][20200507 12:25:25.739 -0400] [CFarmdHealth.java:538] +1{"garbage_collec: {"total_collections_time":16539,"last_minute_collections":5,"last_minute_collections_time.:38,"totalcollections":2313},"current_state":&lt;BR /&gt;
{"event_processing_metric":0.6647058823529413,&lt;STRONG&gt;"message_queues":{"maintenanceWindowManager":"0/-","Hibernate":"0/-","Default Cookbook":"0/-","Alert Workflows":"0/-",.StatCollector":"0/-","bus_thread_pool":"0/-","Event Workflows":"0/-","SituationMgr":"0/-","SituationRootCause":"0/-","Remedy":.0/-","AlertBuilder":"0/-","TeamsMgr":"0/-","xMatters":"0/-","Housekeeper":"0/-","Situation Workflows":"0/-","Indexer":"0/-","MaintManager":"0/-","NCAlertBuilder":"0/-","SMCEnricher":"0/-","xmattersINS":"0/-",.AlertRulesEngine":"0/-"},"in_memory_entropies.:781,"cookbook_resolu _queue":0,"active_async_tasks_count":0},"interval_totals":{"created events":621,"created_external_situations.:0,"created_situations":0&lt;/STRONG&gt;,"&lt;STRONG&gt;messages_processed": {"maintenanceWindowManager":621,"Default Cookbook":548,"Alert Workflows":621,"StatCollector":0,"Event Workflows":597,"situationRootCause":0,"SituationMgr":0,"AlertBuilder":597,"TeamsMgr":0,"xMatters":0,"Indexer":666,"Situation Workflows":0,"maintManager":666,"SMCEnricher":621,NCAlertBuilder":597,xMattersINS":0,"AlertRulesEngine":548},"alerts_added_to situations":0,"situation_db_update_failure":0},JVM_memor]&lt;/STRONG&gt; {"heap_used":314179032,"heap_committed":488636416,"heap_init":195035136,"nonheap_committed":290652160,"heap_max":3107979264,"nonheap_init":7667712,"nonheap_used":263293720,"nonheap_max" 1},"totals":{"created_events":178016,"created_external_situations":0,"created_situations":0,"alerts_added_to situations":0,"situation_db_update_failure":0}}1+&lt;/P&gt;

&lt;P&gt;Now i have to build the kind of tables in the attachment out of above highlighted text in the event,  Can you please help&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/290686-s.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:23:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495614#M138155</guid>
      <dc:creator>pench2k19</dc:creator>
      <dc:date>2020-09-30T05:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: need to help to extract few fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495615#M138156</link>
      <description>&lt;P&gt;@jkat54 @woodcock @sideview @vnravikumar  can you please help&lt;/P&gt;</description>
      <pubDate>Sat, 09 May 2020 09:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495615#M138156</guid>
      <dc:creator>pench2k19</dc:creator>
      <dc:date>2020-05-09T09:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: need to help to extract few fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495616#M138157</link>
      <description>&lt;P&gt;What search have you tried and what questions do you have about the work you've attempted?&lt;/P&gt;

&lt;P&gt;No one wants to do your job for you, but we'd all love to help you     if you've got a specific problem.&lt;/P&gt;</description>
      <pubDate>Sat, 09 May 2020 10:35:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495616#M138157</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-05-09T10:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: need to help to extract few fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495617#M138158</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199197"&gt;@jkat54&lt;/a&gt; i have tried the followin in props.conf and try create fields using that&lt;/P&gt;

&lt;P&gt;[pench_test]&lt;BR /&gt;
DATETIME_CONFIG = &lt;BR /&gt;
LINE_BREAKER = ([\r\n]+)&lt;BR /&gt;
NO_BINARY_CHECK = true&lt;BR /&gt;
SEDCMD = y/:/=/&lt;BR /&gt;
category = Custom&lt;BR /&gt;
pulldown_type = true&lt;BR /&gt;
sedcmd = y/:/=/&lt;/P&gt;

&lt;P&gt;But  its not creating most of the necessery fields to write the SPL query and seeking help.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:23:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495617#M138158</guid>
      <dc:creator>pench2k19</dc:creator>
      <dc:date>2020-09-30T05:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: need to help to extract few fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495618#M138159</link>
      <description>&lt;P&gt;attaching image for your reference&lt;IMG src="https://ibb.co/QHTs0B5" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 14:50:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495618#M138159</guid>
      <dc:creator>pench2k19</dc:creator>
      <dc:date>2020-05-11T14:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: need to help to extract few fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495619#M138160</link>
      <description>&lt;P&gt;Have you tried using regex to capture and the extract the fields you need? |rex field=_raw "regex with capture groups goes here"&lt;BR /&gt;
Or you can go to Settings&amp;gt;Fields&amp;gt;Field Extractions and create a new fields there by extracting what you need. &lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 15:13:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495619#M138160</guid>
      <dc:creator>robinettdonWY</dc:creator>
      <dc:date>2020-05-11T15:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: need to help to extract few fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495620#M138161</link>
      <description>&lt;P&gt;use &lt;CODE&gt;code sample&lt;/CODE&gt; and check your sample before ask the question.&lt;/P&gt;

&lt;P&gt;your log is wrong and some missing string.(where is &lt;CODE&gt;[&lt;/CODE&gt; vs &lt;CODE&gt;,JVM_memor]&lt;/CODE&gt; ? )&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 21:02:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/need-to-help-to-extract-few-fields/m-p/495620#M138161</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-11T21:02:38Z</dc:date>
    </item>
  </channel>
</rss>

