<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to read and extract table format logs in splunk? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-read-and-extract-table-format-logs-in-Splunk/m-p/636642#M221101</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;This is my log file and i onboarded data in splunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;29-Mar-2023 04:56:34:PM: |Services Status in Server

Status   Name               DisplayName                           
------   ----               -----------                           
Stopped  ALG                Application Layer Gateway Service     
Running  Appinfo            Application Information               


29-Mar-2023 04:56:34:PM: |Application Disk Space utilization %

DeviceID VolumeName FreeSpace (Gb) Total (Gb) FreePercent
-------- ---------- -------------- ---------- -----------
C:       System     389.45         475.14           81.97
P:       Offline    389.45         475.14           81.97


29-Mar-2023 04:56:34:PM: |Application Running Process Status

Handles  NPM(K)    PM(K)      WS(K)     CPU(s)     Id  SI ProcessName                                                                                                                          
-------  ------    -----      -----     ------     --  -- -----------                                                                                                                          
   1376      54   175332     238112   3,296.30   7516   4 Teams                                                                                                                                
   9558     194   510488     458660   2,687.58  16488   4 OUTLOOK                                                                                                                              
    926      47    46352      60284   1,959.77   2124   4 cptrayUI                                                                                                                             
   1312      48   232896     175384   1,427.73   2684   4 msedge                                                                                                                               
   3473     560   163948     282908   1,234.33  14368   4 msedge                                                                                                                               


29-Mar-2023 04:56:35:PM: |CPU Utilization %

Average
-------
     11


29-Mar-2023 04:56:36:PM: |Memory Utilization %

MemoryUsage %
-------------
61.44        


29-Mar-2023 04:56:36:PM: |Path Installed on System in Last 90 days

Source        Description      HotFixID      InstalledBy          InstalledOn               
------        -----------      --------      -----------          -----------               
              Update           KB           NT AUTHORITY\SYSTEM  16/02/2023 12:00:00 AM    
              Security Update  KB           NT AUTHORITY\SYSTEM  23/03/2023 12:00:00 AM    
              Update           KB           NT AUTHORITY\SYSTEM  23/03/2023 12:00:00 AM    
&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 31 Mar 2023 02:36:48 GMT</pubDate>
    <dc:creator>karthi2809</dc:creator>
    <dc:date>2023-03-31T02:36:48Z</dc:date>
    <item>
      <title>How to read and extract table format logs in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-read-and-extract-table-format-logs-in-Splunk/m-p/636621#M221095</link>
      <description>&lt;P&gt;Thanks in Advance,&lt;/P&gt;
&lt;P&gt;How to read and extract table format logs in splunk?&lt;/P&gt;
&lt;P&gt;And i need DeviceID as field and with values as&amp;nbsp; same for all fields&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;3/29/23&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4:56:34.000 AM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;SPAN class=""&gt;29-Mar-2023&lt;/SPAN&gt; &lt;SPAN class=""&gt;04:56:34:PM:&lt;/SPAN&gt; |&lt;SPAN class=""&gt;Application&lt;/SPAN&gt; &lt;SPAN class=""&gt;Disk&lt;/SPAN&gt; &lt;SPAN class=""&gt;Space&lt;/SPAN&gt; &lt;SPAN class=""&gt;utilization&lt;/SPAN&gt; &lt;SPAN class=""&gt;%&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;SPAN class=""&gt;DeviceID&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;VolumeName&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;FreeSpace&lt;/SPAN&gt; (&lt;SPAN class=""&gt;Gb&lt;/SPAN&gt;)&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN class=""&gt;Total&lt;/SPAN&gt; (&lt;SPAN class=""&gt;Gb&lt;/SPAN&gt;)&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;FreePercent&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;--------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ----------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;--------------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ----------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;----------&lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;SPAN class=""&gt;C:&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;System&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;389.45&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN class=""&gt;475.14&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN class=""&gt;81.97&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;SPAN class=""&gt;P:&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;Offline&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;389.45&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN class=""&gt;475.14&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN class=""&gt;81.97&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;3/29/23&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4:56:34.000 AM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;SPAN class=""&gt;29-Mar-2023&lt;/SPAN&gt; &lt;SPAN class=""&gt;04:56:34:PM:&lt;/SPAN&gt; |&lt;SPAN class=""&gt;Services&lt;/SPAN&gt; &lt;SPAN class=""&gt;Status&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;Server&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Status&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Name&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN class=""&gt;DisplayName&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;------&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;----&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;----------&lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Stopped&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN class=""&gt;ALG&lt;/SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;SPAN class=""&gt;Application&lt;/SPAN&gt; &lt;SPAN class=""&gt;Layer&lt;/SPAN&gt; &lt;SPAN class=""&gt;Gateway&lt;/SPAN&gt; &lt;SPAN class=""&gt;Service&lt;/SPAN&gt; &lt;SPAN class=""&gt;Running&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Running&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Appinfo&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Application Information&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 07:36:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-read-and-extract-table-format-logs-in-Splunk/m-p/636621#M221095</guid>
      <dc:creator>karthi2809</dc:creator>
      <dc:date>2023-03-30T07:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to read and extract table format logs in splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-read-and-extract-table-format-logs-in-Splunk/m-p/636639#M221100</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/205249"&gt;@karthi2809&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;probably the solution could be kvform command (&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/SearchReference/Kvform" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/SearchReference/Kvform&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;Could you share some sample of your data?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 06:55:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-read-and-extract-table-format-logs-in-Splunk/m-p/636639#M221100</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-30T06:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to read and extract table format logs in splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-read-and-extract-table-format-logs-in-Splunk/m-p/636642#M221101</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;This is my log file and i onboarded data in splunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;29-Mar-2023 04:56:34:PM: |Services Status in Server

Status   Name               DisplayName                           
------   ----               -----------                           
Stopped  ALG                Application Layer Gateway Service     
Running  Appinfo            Application Information               


29-Mar-2023 04:56:34:PM: |Application Disk Space utilization %

DeviceID VolumeName FreeSpace (Gb) Total (Gb) FreePercent
-------- ---------- -------------- ---------- -----------
C:       System     389.45         475.14           81.97
P:       Offline    389.45         475.14           81.97


29-Mar-2023 04:56:34:PM: |Application Running Process Status

Handles  NPM(K)    PM(K)      WS(K)     CPU(s)     Id  SI ProcessName                                                                                                                          
-------  ------    -----      -----     ------     --  -- -----------                                                                                                                          
   1376      54   175332     238112   3,296.30   7516   4 Teams                                                                                                                                
   9558     194   510488     458660   2,687.58  16488   4 OUTLOOK                                                                                                                              
    926      47    46352      60284   1,959.77   2124   4 cptrayUI                                                                                                                             
   1312      48   232896     175384   1,427.73   2684   4 msedge                                                                                                                               
   3473     560   163948     282908   1,234.33  14368   4 msedge                                                                                                                               


29-Mar-2023 04:56:35:PM: |CPU Utilization %

Average
-------
     11


29-Mar-2023 04:56:36:PM: |Memory Utilization %

MemoryUsage %
-------------
61.44        


29-Mar-2023 04:56:36:PM: |Path Installed on System in Last 90 days

Source        Description      HotFixID      InstalledBy          InstalledOn               
------        -----------      --------      -----------          -----------               
              Update           KB           NT AUTHORITY\SYSTEM  16/02/2023 12:00:00 AM    
              Security Update  KB           NT AUTHORITY\SYSTEM  23/03/2023 12:00:00 AM    
              Update           KB           NT AUTHORITY\SYSTEM  23/03/2023 12:00:00 AM    
&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 02:36:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-read-and-extract-table-format-logs-in-Splunk/m-p/636642#M221101</guid>
      <dc:creator>karthi2809</dc:creator>
      <dc:date>2023-03-31T02:36:48Z</dc:date>
    </item>
  </channel>
</rss>

