<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Field extraction in tabular format data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-in-tabular-format-data/m-p/72943#M18260</link>
    <description>&lt;P&gt;Hi ,&lt;BR /&gt;
I have events in following format&lt;BR /&gt;
Subject Maths English Science &lt;BR /&gt;
Marks1  95      98       96&lt;BR /&gt;
Marks2  9        8        10&lt;/P&gt;

&lt;P&gt;I want to extract subject name and marks2 value and display in an tabular format for all the events.&lt;BR /&gt;
How can this be achieved.&lt;BR /&gt;
Output table expected is&lt;BR /&gt;
"Timestamp of event" Maths English Science&lt;BR /&gt;
25-12-2012               9       8      10&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Tue, 25 Dec 2012 11:14:29 GMT</pubDate>
    <dc:creator>splunk_learner</dc:creator>
    <dc:date>2012-12-25T11:14:29Z</dc:date>
    <item>
      <title>Field extraction in tabular format data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-in-tabular-format-data/m-p/72943#M18260</link>
      <description>&lt;P&gt;Hi ,&lt;BR /&gt;
I have events in following format&lt;BR /&gt;
Subject Maths English Science &lt;BR /&gt;
Marks1  95      98       96&lt;BR /&gt;
Marks2  9        8        10&lt;/P&gt;

&lt;P&gt;I want to extract subject name and marks2 value and display in an tabular format for all the events.&lt;BR /&gt;
How can this be achieved.&lt;BR /&gt;
Output table expected is&lt;BR /&gt;
"Timestamp of event" Maths English Science&lt;BR /&gt;
25-12-2012               9       8      10&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 25 Dec 2012 11:14:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-extraction-in-tabular-format-data/m-p/72943#M18260</guid>
      <dc:creator>splunk_learner</dc:creator>
      <dc:date>2012-12-25T11:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction in tabular format data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-in-tabular-format-data/m-p/72944#M18261</link>
      <description>&lt;P&gt;You should be able to use &lt;CODE&gt;multikv&lt;/CODE&gt; for this.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Multikv"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Multikv&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Dec 2012 11:18:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-extraction-in-tabular-format-data/m-p/72944#M18261</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-12-25T11:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction in tabular format data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Field-extraction-in-tabular-format-data/m-p/72945#M18262</link>
      <description>&lt;P&gt;Thanks .This was what i wanted.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Dec 2012 06:10:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Field-extraction-in-tabular-format-data/m-p/72945#M18262</guid>
      <dc:creator>splunk_learner</dc:creator>
      <dc:date>2012-12-26T06:10:53Z</dc:date>
    </item>
  </channel>
</rss>

