<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Split string into fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705426#M238840</link>
    <description>&lt;P&gt;Do you mean?&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;fieldA&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;fieldB&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;fieldC&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;1:10&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;1:3&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;1:2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;1:10&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;1:2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;1:10&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;1:2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;1:1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Wed, 27 Nov 2024 17:18:02 GMT</pubDate>
    <dc:creator>dural_yyz</dc:creator>
    <dc:date>2024-11-27T17:18:02Z</dc:date>
    <item>
      <title>Split string into fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705425#M238839</link>
      <description>&lt;TABLE width="345"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="345"&gt;fieldA:1:10 fieldB:1:3 fieldC:1:2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;fieldA:1:10 fieldC:1:2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;fieldA:1:10 fieldC:1:2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;fieldC:1:1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to end up with a field called fieldA, fieldb, and fieldC where the field name is the actual text found in the string as i cant predict which event will contain which combination&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 16:49:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705425#M238839</guid>
      <dc:creator>darkins</dc:creator>
      <dc:date>2024-11-27T16:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Split string into fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705426#M238840</link>
      <description>&lt;P&gt;Do you mean?&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;fieldA&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;fieldB&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;fieldC&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;1:10&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;1:3&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;1:2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;1:10&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;1:2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;1:10&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;1:2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;1:1&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 27 Nov 2024 17:18:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705426#M238840</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-11-27T17:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Split string into fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705428#M238841</link>
      <description>&lt;P&gt;Assuming your data is in the _raw field&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval parts=split(_raw, " ")
| mvexpand parts
| eval name=mvindex(split(parts,":"),0)
| eval value=mvjoin(mvindex(split(parts,":"),1,2),":")
| eval {name}=value&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 27 Nov 2024 17:30:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705428#M238841</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-27T17:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Split string into fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705436#M238842</link>
      <description>&lt;P&gt;this is awesome, but is there a way to make the results columns (additional fields on my results)&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 19:23:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705436#M238842</guid>
      <dc:creator>darkins</dc:creator>
      <dc:date>2024-11-27T19:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Split string into fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705443#M238844</link>
      <description>&lt;P&gt;Please share some raw anonymised events so we can see what you are dealing with so we can try and help you further. Please use the code block &amp;lt;/&amp;gt; above to preserve the format of the events so that we can suggest the correct field extractions for you.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 21:14:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705443#M238844</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-27T21:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Split string into fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705451#M238848</link>
      <description>&lt;P&gt;If you want to add these fields to a table you are creating but don't know what the fields are called, then you can use&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;technique, but change it slightly so that it is&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;...
| eval cust_field_{name}=value
| table fields_you_want cust_field_*
| rename cust_field_* as *&lt;/LI-CODE&gt;&lt;P&gt;which will effectively give you &lt;STRONG&gt;cust_field_&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;fieldA&lt;/STRONG&gt; and so on with that consistent prefix, then you can use the table statement to table out the fields you want and all those custom fields and then use wildcard rename to get rid of the prefix.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 22:31:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Split-string-into-fields/m-p/705451#M238848</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-11-27T22:31:27Z</dc:date>
    </item>
  </channel>
</rss>

