<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log format for Splunk key=value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Log-format-for-Splunk-key-value/m-p/560803#M159394</link>
    <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;do you advice this log format:&lt;/P&gt;&lt;P&gt;key=value instead of key="value" ? Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jul 2021 14:38:35 GMT</pubDate>
    <dc:creator>splunkreal</dc:creator>
    <dc:date>2021-07-26T14:38:35Z</dc:date>
    <item>
      <title>Log format for Splunk key=value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Log-format-for-Splunk-key-value/m-p/560803#M159394</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;do you advice this log format:&lt;/P&gt;&lt;P&gt;key=value instead of key="value" ? Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 14:38:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Log-format-for-Splunk-key-value/m-p/560803#M159394</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2021-07-26T14:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Log format for Splunk key=value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Log-format-for-Splunk-key-value/m-p/560804#M159395</link>
      <description>&lt;P&gt;Yes&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/171872"&gt;@splunkreal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;key="value" will more&amp;nbsp;&lt;/SPAN&gt;suggested than&amp;nbsp;&lt;SPAN&gt; key=value.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you go with key=value and in case the value has SPACE then Splunk field auto&amp;nbsp;&lt;/SPAN&gt;discovery will consider only first word of that value. In this case you have to write your own field extraction.&lt;/P&gt;&lt;P&gt;Here, I suggest you to create a sample file and index it with sample data (with double quotes and without&amp;nbsp;double quotes) you will get it what is the best way to store value.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;KV&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 14:38:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Log-format-for-Splunk-key-value/m-p/560804#M159395</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2021-07-26T14:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Log format for Splunk key=value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Log-format-for-Splunk-key-value/m-p/560805#M159396</link>
      <description>&lt;P&gt;It depends.&amp;nbsp; K=V is simpler to parse, but if the value contains spaces or commas then it must be quoted.&amp;nbsp; If you must choose one or the other then go with K="V".&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 14:40:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Log-format-for-Splunk-key-value/m-p/560805#M159396</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-07-26T14:40:21Z</dc:date>
    </item>
  </channel>
</rss>

