<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Field in field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65970#M16376</link>
    <description>&lt;P&gt;I have following message format.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2013-06-17 15:33:01+0200 appid="myapplication" responsetimems="155" message="Calling method="calculate" class="math" data="size="98123" rows="9811" firstcolumn="customername"""
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk parsed that into following fields&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;appid = myapplication  
responsetimesms = 155  
message = Calling method=  
class = math  
data = size=  
rows = 9811  
firstcolumn = customername  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But I want to&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;appid = myapplication  
responsetimesms 155  
message = Calling method="calculate" class="math" data="size="98123" rows="9811" firstcolumn="customername"  
method = calculate  
class = math  
data = size="98123" rows="9811" firstcolumn="customername"  
size = 98123  
rows = 9811  
firstcolumn = customername  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How can I do that?&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jun 2013 19:34:22 GMT</pubDate>
    <dc:creator>MicTech</dc:creator>
    <dc:date>2013-06-17T19:34:22Z</dc:date>
    <item>
      <title>Field in field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65970#M16376</link>
      <description>&lt;P&gt;I have following message format.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2013-06-17 15:33:01+0200 appid="myapplication" responsetimems="155" message="Calling method="calculate" class="math" data="size="98123" rows="9811" firstcolumn="customername"""
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk parsed that into following fields&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;appid = myapplication  
responsetimesms = 155  
message = Calling method=  
class = math  
data = size=  
rows = 9811  
firstcolumn = customername  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But I want to&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;appid = myapplication  
responsetimesms 155  
message = Calling method="calculate" class="math" data="size="98123" rows="9811" firstcolumn="customername"  
method = calculate  
class = math  
data = size="98123" rows="9811" firstcolumn="customername"  
size = 98123  
rows = 9811  
firstcolumn = customername  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How can I do that?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2013 19:34:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65970#M16376</guid>
      <dc:creator>MicTech</dc:creator>
      <dc:date>2013-06-17T19:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Field in field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65971#M16377</link>
      <description>&lt;P&gt;Yes. You can do it. Either through &lt;CODE&gt;rex&lt;/CODE&gt; extractions in each search, or through doing some configuration in props.conf. That would involve EXTRACTs where you specify exactly what you want extracted (pretty much the same regex syntax as for &lt;CODE&gt;rex&lt;/CODE&gt;). You might want to set KV_MODE to &lt;CODE&gt;none&lt;/CODE&gt; as well.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/admin/Propsconf"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.3/admin/Propsconf&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;EXTRACT-&amp;lt;class&amp;gt; = [&amp;lt;regex&amp;gt;|&amp;lt;regex&amp;gt; in &amp;lt;src_field&amp;gt;]
* Used to create extracted fields (search-time field extractions) that do not reference
  transforms.conf stanzas.
* Performs a regex-based field extraction from the value of the source field.
* &amp;lt;class&amp;gt; is a unique literal string that identifies the namespace of the field you're extracting.
  **Note:** &amp;lt;class&amp;gt; values do not have to follow field name syntax restrictions. You can use 
  characters other than a-z, A-Z, and 0-9, and spaces are allowed. &amp;lt;class&amp;gt; values are not subject
  to key cleaning. 
* The &amp;lt;regex&amp;gt; is required to have named capturing groups. When the &amp;lt;regex&amp;gt; matches, the named
  capturing groups and their values are added to the event.
* Use '&amp;lt;regex&amp;gt; in &amp;lt;src_field&amp;gt;' to match the regex against the values of a specific field.
  Otherwise it just matches against _raw (all raw event data).
* NOTE: &amp;lt;src_field&amp;gt; can only contain alphanumeric characters (a-z, A-Z, and 0-9).
* If your regex needs to end with 'in &amp;lt;string&amp;gt;' where &amp;lt;string&amp;gt; is *not* a field name, change
  the regex to end with '[i]n &amp;lt;string&amp;gt;' to ensure that Splunk doesn't try to match &amp;lt;string&amp;gt;
  to a field name.

KV_MODE = [none|auto|multi|json|xml]
* Used for search-time field extractions only.
* Specifies the field/value extraction mode for the data.
* Set KV_MODE to one of the following:
        * none: if you want no field/value extraction to take place.
        * auto: extracts field/value pairs separated by equal signs.
        * auto_escaped: extracts fields/value pairs separated by equal signs and honors \" and \\ 
          as escaped sequences within quoted values, e.g field="value with \"nested\" quotes"
        * multi: invokes the multikv search command to expand a tabular event into multiple events.
    * xml : automatically extracts fields from XML data.
    * json: automatically extracts fields from JSON data.
* Setting to 'none' can ensure that one or more user-created regexes are not overridden by
  automatic field/value extraction for a particular host, source, or source type, and also
  increases search performance.
* Defaults to auto.
* The 'xml' and 'json' modes will not extract any fields when used on data that isn't of the 
  correct format (JSON or XML).
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;K&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2013 20:17:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65971#M16377</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-06-17T20:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Field in field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65972#M16378</link>
      <description>&lt;P&gt;Sorry, but it's not what I looking for. See update.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2013 20:30:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65972#M16378</guid>
      <dc:creator>MicTech</dc:creator>
      <dc:date>2013-06-17T20:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Field in field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65973#M16379</link>
      <description>&lt;P&gt;Update: I can change message format. What I looking for is how to convince Splunk to work with inner/nested fields.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2013 20:33:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65973#M16379</guid>
      <dc:creator>MicTech</dc:creator>
      <dc:date>2013-06-17T20:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: Field in field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65974#M16380</link>
      <description>&lt;P&gt;What Kristian writes is correct. You do need to manipulate the extraction mode using a customization. Based on your data sample, there may be two steps to a solution. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Obtain the value pairs first&lt;/LI&gt;
&lt;LI&gt;Obtain the fully-nested field for "message"&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Assume that your data is catalogued with sourcetype "answers-1371500719", then create an entry in props.conf and transforms.conf with the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#props.conf 
[answers-1371500719]
REPORT-get_kv_fields  = get_kv_fields

#transforms.conf
[get_kv_fields]
REGEX = ([a-zA-Z0-9]+)\=\"([a-zA-Z0-9]+)\"
FORMAT = $1::$2
MV_ADD = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This ensures that you obtain all of those fields and corresponsing values that follow this convetion&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;field="value123"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will provide you the appropriate value pairs. Please note that the message field is still incorrect.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/Untitled503.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;The message field can then overriden using an inline regular expression at search time, &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype="answers-1371500719" | rex field=_raw "message\=\"(?&amp;lt;message&amp;gt;.+\"?)\"\""
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or automatically by updating your props.conf entry&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#props.conf 
[answers-1371500719]
REPORT-get_kv_fields  = get_kv_fields
EXTRACT-message_field = message\=\"(?&amp;lt;message&amp;gt;.+\"?)\"\"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In the end you end up with this:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/Untitled504.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;gc&lt;/P&gt;

&lt;P&gt;BTW: Thanks for posting a data sample. It is always easy if we see the data.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2013 21:11:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65974#M16380</guid>
      <dc:creator>Gilberto_Castil</dc:creator>
      <dc:date>2013-06-17T21:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Field in field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65975#M16381</link>
      <description>&lt;P&gt;Thanks for the solution. I also had the same problem and this works for me as well.&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2015 09:15:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-in-field/m-p/65975#M16381</guid>
      <dc:creator>jassiwins</dc:creator>
      <dc:date>2015-05-22T09:15:29Z</dc:date>
    </item>
  </channel>
</rss>

