<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to extract kv from a variable format field using kvform? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-from-a-variable-format-field-using-kvform/m-p/231797#M68760</link>
    <description>&lt;P&gt;I also got this error when I created the directory for forms as described in the documentation - "$SPLUNK_HOME/etc/apps/.../forms". Instead try "$SPLUNK_HOME/etc/apps/.../form", without que final 's'.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.4.3/SearchReference/Kvform" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/6.4.3/SearchReference/Kvform&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 10:44:22 GMT</pubDate>
    <dc:creator>tcmarquesi</dc:creator>
    <dc:date>2020-09-29T10:44:22Z</dc:date>
    <item>
      <title>How to extract kv from a variable format field using kvform?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-from-a-variable-format-field-using-kvform/m-p/231795#M68758</link>
      <description>&lt;P&gt;I need to extract some keys/values from a certain field, however it doesn't have a fixed format. Actually this field can contain multiple sub-fields and assume different lengths according to the data's meaning.&lt;BR /&gt;
I was wondering if I can use &lt;STRONG&gt;kvform&lt;/STRONG&gt; function, so in the &lt;EM&gt;.form&lt;/EM&gt; file I could input all the regexes that match my data.&lt;BR /&gt;
Am I thinking right, will splunk's kvform work like this? In positive case, what is the proper sintax of .form file? The documentation pages aren't pretty clear...&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 19:53:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-from-a-variable-format-field-using-kvform/m-p/231795#M68758</guid>
      <dc:creator>tcmarquesi</dc:creator>
      <dc:date>2016-08-17T19:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract kv from a variable format field using kvform?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-from-a-variable-format-field-using-kvform/m-p/231796#M68759</link>
      <description>&lt;P&gt;I too would like to know how to format the .form file.   I am getting error:  Cannot find regex reference: to the lines in the .form file I am creating.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 19:15:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-from-a-variable-format-field-using-kvform/m-p/231796#M68759</guid>
      <dc:creator>TobiasBoone</dc:creator>
      <dc:date>2016-08-24T19:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract kv from a variable format field using kvform?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-from-a-variable-format-field-using-kvform/m-p/231797#M68760</link>
      <description>&lt;P&gt;I also got this error when I created the directory for forms as described in the documentation - "$SPLUNK_HOME/etc/apps/.../forms". Instead try "$SPLUNK_HOME/etc/apps/.../form", without que final 's'.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.4.3/SearchReference/Kvform" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/6.4.3/SearchReference/Kvform&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:44:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-kv-from-a-variable-format-field-using-kvform/m-p/231797#M68760</guid>
      <dc:creator>tcmarquesi</dc:creator>
      <dc:date>2020-09-29T10:44:22Z</dc:date>
    </item>
  </channel>
</rss>

