<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Separate Fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Separate-Fields/m-p/66283#M16451</link>
    <description>&lt;P&gt;&lt;CODE&gt;Field1=abcdefg&amp;amp;Field2=12345;field3=98373&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;does not match any of your regular expressions, as &lt;CODE&gt;field3&lt;/CODE&gt; is lower case in the above example. I will assume that you meant:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;Field1=abcdefg&amp;amp;Field2=12345;Field3=98373&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;instead. Now your first regular expression will &lt;EM&gt;almost&lt;/EM&gt; work, although it has a spurious &lt;CODE&gt;"&lt;/CODE&gt; in it. The second regular expression has lost the &lt;CODE&gt;=&lt;/CODE&gt; and put the field separator in the wrong places.&lt;BR /&gt;
You could do this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;yoursearchhere
| rex  "Field1=(?&amp;lt;Field1&amp;gt;.*)[;&amp;amp;]Field2=(?&amp;lt;Field2&amp;gt;.*)[;&amp;amp;]Field3=(?&amp;lt;Field3&amp;gt;.*)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is another answer that may be helpful:&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/30409/splunk-field-seperators"&gt;http://splunk-base.splunk.com/answers/30409/splunk-field-seperators&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here is an example of using DELIMS in transforms.conf. It applies to an event where field/value pairs are separated by ';' symbols, and the field names are separated from their corresponding values by '=' symbols:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[pipe_eq]
DELIMS = ";", "="
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You can find out more about DELIMS &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.1/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles"&gt;here&lt;/A&gt;. Also look at the documentation for transforms.conf&lt;/P&gt;</description>
    <pubDate>Mon, 17 Dec 2012 22:12:13 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2012-12-17T22:12:13Z</dc:date>
    <item>
      <title>Separate Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Separate-Fields/m-p/66282#M16450</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm new to splunk, so please excuse the basic question.  I have some data in the following format:&lt;BR /&gt;
Field1=abcdefg;Field2=12345;field3=98373&lt;BR /&gt;
Field1=abcdefg&amp;amp;Field2=12345;field3=98373&lt;/P&gt;

&lt;P&gt;Note the different separators.  I can quite easily extract one of these using the following command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex field=_raw "Field1=(?&amp;lt;Field1&amp;gt;.*)Field2=(?&amp;lt;Field2&amp;gt;.*)"Field3=(?&amp;lt;Field3&amp;gt;.*)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I thought I could expand on this, in order to extract both of them at the same time, so I tried this, but it does not seem to work:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex field=_raw "Field1[;&amp;amp;](?&amp;lt;Field1&amp;gt;.*)Field2[;&amp;amp;](?&amp;lt;Field2&amp;gt;.*)"Field3[;&amp;amp;](?&amp;lt;Field3&amp;gt;.*)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Could someone please help with this?  I imagine there probably is a better way to do this, but I am still trying different ways.  Is there a way to just give my delimiters and have it extract everything in it's own field?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2012 21:45:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Separate-Fields/m-p/66282#M16450</guid>
      <dc:creator>jaykay</dc:creator>
      <dc:date>2012-12-17T21:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Separate Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Separate-Fields/m-p/66283#M16451</link>
      <description>&lt;P&gt;&lt;CODE&gt;Field1=abcdefg&amp;amp;Field2=12345;field3=98373&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;does not match any of your regular expressions, as &lt;CODE&gt;field3&lt;/CODE&gt; is lower case in the above example. I will assume that you meant:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;Field1=abcdefg&amp;amp;Field2=12345;Field3=98373&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;instead. Now your first regular expression will &lt;EM&gt;almost&lt;/EM&gt; work, although it has a spurious &lt;CODE&gt;"&lt;/CODE&gt; in it. The second regular expression has lost the &lt;CODE&gt;=&lt;/CODE&gt; and put the field separator in the wrong places.&lt;BR /&gt;
You could do this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;yoursearchhere
| rex  "Field1=(?&amp;lt;Field1&amp;gt;.*)[;&amp;amp;]Field2=(?&amp;lt;Field2&amp;gt;.*)[;&amp;amp;]Field3=(?&amp;lt;Field3&amp;gt;.*)"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is another answer that may be helpful:&lt;BR /&gt;&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/30409/splunk-field-seperators"&gt;http://splunk-base.splunk.com/answers/30409/splunk-field-seperators&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here is an example of using DELIMS in transforms.conf. It applies to an event where field/value pairs are separated by ';' symbols, and the field names are separated from their corresponding values by '=' symbols:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[pipe_eq]
DELIMS = ";", "="
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You can find out more about DELIMS &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.1/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles"&gt;here&lt;/A&gt;. Also look at the documentation for transforms.conf&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2012 22:12:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Separate-Fields/m-p/66283#M16451</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-12-17T22:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Separate Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Separate-Fields/m-p/66284#M16452</link>
      <description>&lt;P&gt;Sorry, the errors in that were due to me trying to remember the data off the top of my head.  Turns out the code you posted and the code I used are the same, and that didn't quite work. Here is the actual format of the data:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;field1=field1value=&amp;amp;field2value=0&amp;amp;field3value=0&amp;amp;field4=DataNotRequired
field1=field1value;+Field5=DataNotRequired=djkhkdjkhdkjash
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 18 Dec 2012 10:16:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Separate-Fields/m-p/66284#M16452</guid>
      <dc:creator>jaykay</dc:creator>
      <dc:date>2012-12-18T10:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: Separate Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Separate-Fields/m-p/66285#M16453</link>
      <description>&lt;P&gt;Extracting field1 works, but then a lot of the other fields (2 onwards) are all left in there also.  What if I wanted to just extract that one field and just search the various delimiters at the end of it?  Could I then later pick another field and extract that (whether that data is before or after the already extracted data)?  Unfoortunately, as the data which follows is not always consistent, I cannot input that data into a new field by naming the field.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2012 10:16:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Separate-Fields/m-p/66285#M16453</guid>
      <dc:creator>jaykay</dc:creator>
      <dc:date>2012-12-18T10:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Separate Fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Separate-Fields/m-p/66286#M16454</link>
      <description>&lt;P&gt;Ok so I have been testing this further, and the following works better for me, as it seems to extract mroe fields.  It is still not perfect for the most important fields though.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;search term | extract pairdelim=";+&amp;amp;", kvdelim="=", auto=f
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Using this, the following do not get caught still:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Field72=&amp;amp;Field1=Field1Value&amp;amp;Field52=Field52Value
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note that Field72 is blank, which may be the reason for it not being extracted.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2012 11:54:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Separate-Fields/m-p/66286#M16454</guid>
      <dc:creator>jaykay</dc:creator>
      <dc:date>2012-12-18T11:54:34Z</dc:date>
    </item>
  </channel>
</rss>

