<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extract data from quotation marks in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640407#M221922</link>
    <description>&lt;P&gt;i tried adding the | kv,&lt;/P&gt;&lt;P&gt;and i do not get all the data&amp;nbsp; in the result set.&lt;/P&gt;&lt;P&gt;am not allowed to edit the&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;props.conf&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Apr 2023 18:31:13 GMT</pubDate>
    <dc:creator>Lazous</dc:creator>
    <dc:date>2023-04-18T18:31:13Z</dc:date>
    <item>
      <title>How to extract data from quotation marks?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640379#M221905</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;I am trying to extract the data from the following message:&lt;BR /&gt;the header data is in quotes and for each header data there is a set of secondary data also in quotes.&lt;BR /&gt;The events are presented as follows:&lt;/P&gt;
&lt;P&gt;{Name=SS, PId=236}&lt;BR /&gt;PROD {Type=A_OUTGOING, Id=7934,plan=8975, Conflict=2529, Date=2023-04-18T18:51:00.000+02:00}&lt;BR /&gt;PROD {Type=B_OUTGOING, Id=7934, plan=8975, Conflict=72482, Date=2023-04-18T18:51:00.000+02:00}&lt;BR /&gt;{Name=DAG, PId=55}&lt;BR /&gt;PROD {Type=B_INCOMING, Id=7921, plan=8975, Conflict=64870, Date=2023-04-18T18:51:00.000+02:00}&lt;/P&gt;
&lt;P&gt;The following result is expected:&lt;/P&gt;
&lt;TABLE width="641"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="80"&gt;Name&lt;/TD&gt;
&lt;TD width="34"&gt;&amp;nbsp;&amp;nbsp;PId&lt;/TD&gt;
&lt;TD width="91"&gt;&amp;nbsp;Type&lt;/TD&gt;
&lt;TD width="80"&gt;&amp;nbsp;Id&lt;/TD&gt;
&lt;TD width="80"&gt;&amp;nbsp;plan&lt;/TD&gt;
&lt;TD width="80"&gt;Conflict&lt;/TD&gt;
&lt;TD width="196"&gt;&amp;nbsp;Date&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SS&lt;/TD&gt;
&lt;TD&gt;236&lt;/TD&gt;
&lt;TD&gt;A_OUTGOING&lt;/TD&gt;
&lt;TD&gt;7934&lt;/TD&gt;
&lt;TD&gt;8975&lt;/TD&gt;
&lt;TD&gt;2529&lt;/TD&gt;
&lt;TD&gt;2023-04-18T18:51:00.000+02:00&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;SS&lt;/TD&gt;
&lt;TD&gt;236&lt;/TD&gt;
&lt;TD&gt;B_OUTGOING&lt;/TD&gt;
&lt;TD&gt;7934&lt;/TD&gt;
&lt;TD&gt;8975&lt;/TD&gt;
&lt;TD&gt;72482&lt;/TD&gt;
&lt;TD&gt;2023-04-18T18:51:00.000+02:00&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;DAG&lt;/TD&gt;
&lt;TD&gt;55&lt;/TD&gt;
&lt;TD&gt;B_INCOMING&lt;/TD&gt;
&lt;TD&gt;7921&lt;/TD&gt;
&lt;TD&gt;8975&lt;/TD&gt;
&lt;TD&gt;64870&lt;/TD&gt;
&lt;TD&gt;2023-04-18T18:51:00.000+02:00&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Would you please help?&amp;nbsp;&lt;/SPAN&gt;Thanking you&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 18:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640379#M221905</guid>
      <dc:creator>Lazous</dc:creator>
      <dc:date>2023-04-18T18:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Extract data from quotation marks</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640387#M221909</link>
      <description>&lt;P&gt;Given that this looks like it might be JSON, have you tried using spath?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 17:25:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640387#M221909</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-04-18T17:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Extract data from quotation marks</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640389#M221911</link>
      <description>&lt;P&gt;That data is JSON so the quick/easy/wrong fix is just to add this to your search:&lt;BR /&gt;| kv&lt;BR /&gt;&lt;BR /&gt;But the better answer is to add this to your props.conf for your source/sourcetype:&lt;BR /&gt;KV_MODE = json&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 17:31:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640389#M221911</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-04-18T17:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Extract data from quotation marks</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640407#M221922</link>
      <description>&lt;P&gt;i tried adding the | kv,&lt;/P&gt;&lt;P&gt;and i do not get all the data&amp;nbsp; in the result set.&lt;/P&gt;&lt;P&gt;am not allowed to edit the&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;props.conf&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 18:31:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640407#M221922</guid>
      <dc:creator>Lazous</dc:creator>
      <dc:date>2023-04-18T18:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Extract data from quotation marks</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640408#M221923</link>
      <description>&lt;P&gt;would you please specify how the command would look like in this case ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 18:32:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640408#M221923</guid>
      <dc:creator>Lazous</dc:creator>
      <dc:date>2023-04-18T18:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: Extract data from quotation marks</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640409#M221924</link>
      <description>&lt;P&gt;&lt;SPAN&gt;| makeresults&lt;BR /&gt;| eval raw="{Name=SS, PId=236}&lt;BR /&gt;PROD {Type=A_OUTGOING, Id=7934,plan=8975, Conflict=2529, Date=2023-04-18T18:51:00.000+02:00}&lt;BR /&gt;PROD {Type=B_OUTGOING, Id=7934, plan=8975, Conflict=72482, Date=2023-04-18T18:51:00.000+02:00} {Name=DAG, PId=55}&lt;BR /&gt;PROD {Type=B_INCOMING, Id=7921, plan=8975, Conflict=64870, Date=2023-04-18T18:51:00.000+02:00}"&lt;BR /&gt;| makemv delim="&lt;BR /&gt;" raw&lt;BR /&gt;| mvexpand raw&lt;BR /&gt;| rename raw AS _raw&lt;BR /&gt;| kv&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 18:43:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-data-from-quotation-marks/m-p/640409#M221924</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-04-18T18:43:26Z</dc:date>
    </item>
  </channel>
</rss>

