<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Field extraction in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586221#M204208</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242965"&gt;@ranjithan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if this answer solves your need, please accept it for the other epople of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Feb 2022 13:07:30 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-02-23T13:07:30Z</dc:date>
    <item>
      <title>How to extract all values?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586052#M204146</link>
      <description>&lt;P&gt;&lt;SPAN&gt;----------------------&lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;DISK&lt;/SPAN&gt; &lt;SPAN class=""&gt;INFORMATION&lt;/SPAN&gt;&lt;SPAN&gt; ----------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;DISK=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;/dev/sda&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;NAME=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;sda&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;HCTL=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;0:0:0:0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;TYPE=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;disk&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;VENDOR=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;VMware&lt;/SPAN&gt;&lt;SPAN&gt; " &lt;/SPAN&gt;&lt;SPAN class=""&gt;SIZE=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;210G&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SCSIHOST=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;CHANNEL=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;ID=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;LUN=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;BOOTDISK=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;TRUE&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;DISK=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;/dev/sdb&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;NAME=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;sdb&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;HCTL=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;0:0:1:0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;TYPE=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;disk&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;VENDOR=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;VMware&lt;/SPAN&gt;&lt;SPAN&gt; " &lt;/SPAN&gt;&lt;SPAN class=""&gt;SIZE=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;100G&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;SCSIHOST=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;CHANNEL=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;ID=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;LUN=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;BOOTDISK=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;FALSE&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My log (multiline event) looks like this but Splunk is automatically extracting just the first line . I want to extract all the values.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;for example:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;NAME=sda &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;NAME=sdb&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Could someone please help me with it&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 21:23:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586052#M204146</guid>
      <dc:creator>ranjithan</dc:creator>
      <dc:date>2022-02-22T21:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586056#M204150</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;if your input file or what ever is generating this is like this (one DISK on every line)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;DISK="/dev/sda" NAME="sda" HCTL="0:0:0:0" TYPE="disk" VENDOR="VMware " SIZE="210G" SCSIHOST="0" CHANNEL="0" ID="0" LUN="0" BOOTDISK="TRUE"
DISK="/dev/sdb" NAME="sdb" HCTL="0:0:1:0" TYPE="disk" VENDOR="VMware " SIZE="100G" SCSIHOST="0" CHANNEL="0" ID="1" LUN="0" BOOTDISK="FALSE"&lt;/LI-CODE&gt;&lt;P&gt;then you can use props.conf in HF/IDX (which one is first from your source)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;DATETIME_CONFIG=CURRENT
SHOULD_LINEMERGE=true
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Basically this is what splunk is doing without any configurations.&lt;/P&gt;&lt;P&gt;How you are collecting that disk information?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 15:13:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586056#M204150</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-02-22T15:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586059#M204152</link>
      <description>&lt;P&gt;it is based on shell script output.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 15:19:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586059#M204152</guid>
      <dc:creator>ranjithan</dc:creator>
      <dc:date>2022-02-22T15:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586060#M204153</link>
      <description>&lt;P&gt;Kindly suggest if it could be done via SPL or regex extractions..&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 15:20:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586060#M204153</guid>
      <dc:creator>ranjithan</dc:creator>
      <dc:date>2022-02-22T15:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586061#M204154</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242965"&gt;@ranjithan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;please try this&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?ms)^DISK\=\"(?&amp;lt;DISK&amp;gt;[^\"]+)\"\s+NAME\=\"(?&amp;lt;NAMA&amp;gt;[^\"]+)\"\s+HCTL\=\"(?&amp;lt;HCTL&amp;gt;[^\"]+)\"\s+TYPE\=\"(?&amp;lt;TYPE&amp;gt;[^\"]+)\"\s+VENDOR\=\"(?&amp;lt;VENDOR&amp;gt;[^\"]+)\"\s+SIZE\=\"(?&amp;lt;SIZE&amp;gt;[^\"]+)\"\s+SCSIHOST\=\"(?&amp;lt;SCSIHOST&amp;gt;[^\"]+)\"\s+CHANNEL\=\"(?&amp;lt;CHANNEL&amp;gt;[^\"]+)\"\s+ID\=\"(?&amp;lt;ID&amp;gt;[^\"]+)\"\s+LUN\=\"(?&amp;lt;LUN&amp;gt;[^\"]+)\"\s+BOOTDISK\=\"(?&amp;lt;BOOTDISK&amp;gt;[^\"]+)\""&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/LrfKpR/1" target="_blank"&gt;https://regex101.com/r/LrfKpR/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 15:20:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586061#M204154</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-02-22T15:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586203#M204196</link>
      <description>&lt;P&gt;Thank you. let me try...&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 11:55:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586203#M204196</guid>
      <dc:creator>ranjithan</dc:creator>
      <dc:date>2022-02-23T11:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586221#M204208</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242965"&gt;@ranjithan&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if this answer solves your need, please accept it for the other epople of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 13:07:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-all-values/m-p/586221#M204208</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-02-23T13:07:30Z</dc:date>
    </item>
  </channel>
</rss>

