<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to make a loop in one event? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-make-a-loop-in-one-event/m-p/590470#M205581</link>
    <description>&lt;P&gt;Is event a multivalue field - if so, use mvexpand to expand to multiple events, then you can extract server, host and status from the event field&lt;/P&gt;</description>
    <pubDate>Wed, 23 Mar 2022 15:35:58 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2022-03-23T15:35:58Z</dc:date>
    <item>
      <title>How to make a loop in one event?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-make-a-loop-in-one-event/m-p/590467#M205578</link>
      <description>&lt;P&gt;My log is like this:&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Time&lt;/TD&gt;&lt;TD width="50%"&gt;Event&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;3/23/22 11:00:00.000 AM&lt;/TD&gt;&lt;TD width="50%"&gt;&lt;P&gt;Application 'AAA' is running&lt;/P&gt;&lt;P&gt;Application 'BBB' is stopped&lt;/P&gt;&lt;P&gt;Database 'CCC' is running&lt;/P&gt;&lt;P&gt;Database 'DDD' is running&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;3/23/22 11:10:00.000 AM&lt;/TD&gt;&lt;TD width="50%"&gt;&lt;P&gt;Application 'AAA' is running&lt;/P&gt;&lt;P&gt;Application 'BBB' is running&lt;/P&gt;&lt;P&gt;Database 'CCC' is stopped&lt;/P&gt;&lt;P&gt;Database 'DDD' is running&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to extract a table like&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%"&gt;Time&lt;/TD&gt;&lt;TD width="25%"&gt;Server&lt;/TD&gt;&lt;TD width="25%"&gt;Host&lt;/TD&gt;&lt;TD width="25%"&gt;Status&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;3/23/22 11:00:00.000 AM&lt;/TD&gt;&lt;TD width="25%"&gt;Application&lt;/TD&gt;&lt;TD width="25%"&gt;AAA&lt;/TD&gt;&lt;TD width="25%"&gt;running&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;3/23/22 11:00:00.000 AM&lt;/TD&gt;&lt;TD width="25%"&gt;Application&lt;/TD&gt;&lt;TD width="25%"&gt;BBB&lt;/TD&gt;&lt;TD width="25%"&gt;stopped&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;3/23/22 11:00:00.000 AM&lt;/TD&gt;&lt;TD width="25%"&gt;Database&lt;/TD&gt;&lt;TD width="25%"&gt;CCC&lt;/TD&gt;&lt;TD width="25%"&gt;running&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;3/23/22 11:00:00.000 AM&lt;/TD&gt;&lt;TD width="25%"&gt;Database&lt;/TD&gt;&lt;TD width="25%"&gt;DDD&lt;/TD&gt;&lt;TD width="25%"&gt;running&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;3/23/22 11:10:00.000 AM&lt;/TD&gt;&lt;TD width="25%"&gt;Application&lt;/TD&gt;&lt;TD width="25%"&gt;AAA&lt;/TD&gt;&lt;TD width="25%"&gt;running&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;3/23/22 11:10:00.000 AM&lt;/TD&gt;&lt;TD width="25%"&gt;Application&lt;/TD&gt;&lt;TD width="25%"&gt;BBB&lt;/TD&gt;&lt;TD width="25%"&gt;running&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;3/23/22 11:10:00.000 AM&lt;/TD&gt;&lt;TD width="25%"&gt;Database&lt;/TD&gt;&lt;TD width="25%"&gt;CCC&lt;/TD&gt;&lt;TD width="25%"&gt;stopped&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;3/23/22 11:10:00.000 AM&lt;/TD&gt;&lt;TD width="25%"&gt;Database&lt;/TD&gt;&lt;TD width="25%"&gt;DDD&lt;/TD&gt;&lt;TD width="25%"&gt;running&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to do this? If anyone has idea?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 15:32:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-make-a-loop-in-one-event/m-p/590467#M205578</guid>
      <dc:creator>sabinayang</dc:creator>
      <dc:date>2022-03-23T15:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to make a loop in one event?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-make-a-loop-in-one-event/m-p/590470#M205581</link>
      <description>&lt;P&gt;Is event a multivalue field - if so, use mvexpand to expand to multiple events, then you can extract server, host and status from the event field&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 15:35:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-make-a-loop-in-one-event/m-p/590470#M205581</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-03-23T15:35:58Z</dc:date>
    </item>
  </channel>
</rss>

