<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Extracting multiple similar values from a multi-line event in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extracting-multiple-similar-values-from-a-multi-line-event/m-p/61614#M15212</link>
    <description>&lt;P&gt;I've got a rather tricky (at least for me) data set that I'd like to extract values from.  For this example text &lt;/P&gt;

&lt;P&gt;`&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Elapsed Time Unti Event Locked Display :: Longest 5 Entries: &lt;BR /&gt;
Elapsed Time Unti Event Locked Display :: [Max(0.361), Avg(0.180), Min(0.000)] sec(s)    # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTD_RTD&lt;BR /&gt;
Elapsed Time Unti Event Locked Display :: [Max(0.001), Avg(0.000), Min(0.000)] sec(s)    # Total: 00007      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_WFC_STATUS&lt;BR /&gt;
Elapsed Time Unti Event Locked Display :: [Max(0.000), Avg(0.000), Min(0.000)] sec(s)    # Total: 00001      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTPD_RTPD&lt;BR /&gt;
Elapsed Time Unti Event Locked Display :: [Max(0.000), Avg(0.000), Min(0.000)] sec(s)    # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTD_REVIEW_PERIOD&lt;BR /&gt;
Elapsed Time Unti Event Locked Display :: [Max(0.000), Avg(0.000), Min(0.000)] sec(s)    # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTPD_REVIEW_PERIOD&lt;BR /&gt;
&amp;gt;&amp;gt;&amp;gt; Eventing Processing Time :: Longest 5 Entries: &lt;BR /&gt;
Eventing Processing Time :: [Max(0.421), Avg(0.308), Min(0.194)] sec(s)      # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTD_REVIEW_PERIOD&lt;BR /&gt;
Eventing Processing Time :: [Max(0.198), Avg(0.194), Min(0.190)] sec(s)      # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTPD_REVIEW_PERIOD&lt;BR /&gt;
Eventing Processing Time :: [Max(0.149), Avg(0.142), Min(0.134)] sec(s)      # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTD_RTD&lt;BR /&gt;
Eventing Processing Time :: [Max(0.039), Avg(0.039), Min(0.039)] sec(s)      # Total: 00001      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTPD_RTPD&lt;BR /&gt;
Eventing Processing Time :: [Max(0.017), Avg(0.011), Min(0.000)] sec(s)      # Total: 00007      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_WFC_STATUS&lt;BR /&gt;
User Sessions :: Number of sessions 1&lt;BR /&gt;
`&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I need to extract out the Max,Avg,Min values for each MenuId: in Eventing Processing Time.  Max isn't a multivalue field, but rather only relevent to the MenuId in the same line.  So I'd need something like RT_RTD_REVIEW_PERIOD-Max and RT_RTD_REVIEW_PERIOD-Avg.&lt;/P&gt;

&lt;P&gt;I'm not sure how to do this other than simple brute forcing with multiple regexes.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 13:31:06 GMT</pubDate>
    <dc:creator>mikelanghorst</dc:creator>
    <dc:date>2020-09-28T13:31:06Z</dc:date>
    <item>
      <title>Extracting multiple similar values from a multi-line event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-multiple-similar-values-from-a-multi-line-event/m-p/61614#M15212</link>
      <description>&lt;P&gt;I've got a rather tricky (at least for me) data set that I'd like to extract values from.  For this example text &lt;/P&gt;

&lt;P&gt;`&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Elapsed Time Unti Event Locked Display :: Longest 5 Entries: &lt;BR /&gt;
Elapsed Time Unti Event Locked Display :: [Max(0.361), Avg(0.180), Min(0.000)] sec(s)    # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTD_RTD&lt;BR /&gt;
Elapsed Time Unti Event Locked Display :: [Max(0.001), Avg(0.000), Min(0.000)] sec(s)    # Total: 00007      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_WFC_STATUS&lt;BR /&gt;
Elapsed Time Unti Event Locked Display :: [Max(0.000), Avg(0.000), Min(0.000)] sec(s)    # Total: 00001      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTPD_RTPD&lt;BR /&gt;
Elapsed Time Unti Event Locked Display :: [Max(0.000), Avg(0.000), Min(0.000)] sec(s)    # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTD_REVIEW_PERIOD&lt;BR /&gt;
Elapsed Time Unti Event Locked Display :: [Max(0.000), Avg(0.000), Min(0.000)] sec(s)    # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTPD_REVIEW_PERIOD&lt;BR /&gt;
&amp;gt;&amp;gt;&amp;gt; Eventing Processing Time :: Longest 5 Entries: &lt;BR /&gt;
Eventing Processing Time :: [Max(0.421), Avg(0.308), Min(0.194)] sec(s)      # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTD_REVIEW_PERIOD&lt;BR /&gt;
Eventing Processing Time :: [Max(0.198), Avg(0.194), Min(0.190)] sec(s)      # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTPD_REVIEW_PERIOD&lt;BR /&gt;
Eventing Processing Time :: [Max(0.149), Avg(0.142), Min(0.134)] sec(s)      # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTD_RTD&lt;BR /&gt;
Eventing Processing Time :: [Max(0.039), Avg(0.039), Min(0.039)] sec(s)      # Total: 00001      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTPD_RTPD&lt;BR /&gt;
Eventing Processing Time :: [Max(0.017), Avg(0.011), Min(0.000)] sec(s)      # Total: 00007      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_WFC_STATUS&lt;BR /&gt;
User Sessions :: Number of sessions 1&lt;BR /&gt;
`&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I need to extract out the Max,Avg,Min values for each MenuId: in Eventing Processing Time.  Max isn't a multivalue field, but rather only relevent to the MenuId in the same line.  So I'd need something like RT_RTD_REVIEW_PERIOD-Max and RT_RTD_REVIEW_PERIOD-Avg.&lt;/P&gt;

&lt;P&gt;I'm not sure how to do this other than simple brute forcing with multiple regexes.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:31:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-multiple-similar-values-from-a-multi-line-event/m-p/61614#M15212</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2020-09-28T13:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting multiple similar values from a multi-line event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-multiple-similar-values-from-a-multi-line-event/m-p/61615#M15213</link>
      <description>&lt;P&gt;I believe the following would work, but only as an index-time extraction.  (Not tested)&lt;/P&gt;

&lt;P&gt;in Transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[stanza_name]
REPEAT_MATCH = true
REGEX = Elapsed\sProcessing\sTime\s::\s\[\w+\(([^\)]+)\),\s\w+\(([^\)]+)\),\s\w+\(([^\)]+)\)\].+?#\s\w+:\s(\d+)\s+\w+:\s[\w\.]+-([\w_]+)
FORMAT = $5-Max::$1 $5-Avg::$2 $5-Min::$3 $5-Total::$4
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;My regex may not be the most clean/efficient, but it appears to capture everything correctly on regexr.&lt;/P&gt;

&lt;P&gt;So from:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Eventing Processing Time :: [Max(0.421), Avg(0.308), Min(0.194)] sec(s)      # Total: 00002      MenuId: rtdMenu.rtnIntervalDispatch.rtnIntervalDispExecuctionControl-RT_RTD_REVIEW_PERIOD
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;it will extract:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$1 = 0.421
$2 = 0.308
$3 = 0.194
$4 = 00002
$5 = RT_RTD_REVIEW_PERIOD
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So $5-Max::$1 should become 'RT_RTD_REVIEW_PERIOD-Max = 0.421'&lt;/P&gt;

&lt;P&gt;According to the documentation on transforms.conf, you can only do concatenated fields with index-time extractions. &lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2013 17:36:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-multiple-similar-values-from-a-multi-line-event/m-p/61615#M15213</guid>
      <dc:creator>emiller42</dc:creator>
      <dc:date>2013-03-14T17:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting multiple similar values from a multi-line event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-multiple-similar-values-from-a-multi-line-event/m-p/61616#M15214</link>
      <description>&lt;P&gt;Hmm, only pulling the first line.  REPEAT_MATCH = true is set, but no affect.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2013 22:08:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-multiple-similar-values-from-a-multi-line-event/m-p/61616#M15214</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2013-03-15T22:08:51Z</dc:date>
    </item>
  </channel>
</rss>

