<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to extract values from my sample log? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258152#M77337</link>
    <description>&lt;P&gt;i just tried but it is not showing extracted fields in left side.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2017 00:47:09 GMT</pubDate>
    <dc:creator>rajgowd1</dc:creator>
    <dc:date>2017-01-24T00:47:09Z</dc:date>
    <item>
      <title>How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258144#M77329</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
can you help us to extract values from log like ACTION, URI and response_time&lt;/P&gt;

&lt;P&gt;i used extract kvdelim=":" pairdelim="," but it is not extracting response time.&lt;/P&gt;

&lt;P&gt;ACTION=DELETE,POST,GET etc&lt;BR /&gt;
URI's = endpoints&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;6&amp;gt;2017-01-23T19:17:45Z v204vtn756h doppler[19]: {"cf_app_id":"012b7380-c96c-46e6-a57e-b96fd1f7266c","cf_app_name":"nam-ccp-psg-sit","cf_ignored_app":false,"cf_org_id":"fd12558e-ddaf-4dd2-91b3-85f28ccd27f3","cf_org_name":"NAM-US-CCP","cf_origin":"firehose","cf_space_id":"f9e2c3b9-ff7a-46b2-b359-9ec4ec13487b","cf_space_name":"lab","deployment":"cf","event_type":"LogMessage","ip":"168.72.186.232","job":"router-partition-ee9c6bad3843f162447f","job_index":"1","level":"info","message_type":"OUT","msg":"nam-ccp-psg-sit.cfapps-gcg-nonprd.nam.nsroot.net - [23/01/2017:19:17:45 +0000] \"POST /public/sso/keepalive HTTP/1.1\" 200 0 0 \"-\" \"Apache-HttpClient/4.1.1 (java 1.5)\" 153.40.245.130:15583 x_forwarded_for:\"169.193.222.122\" x_forwarded_proto:\"http\" vcap_request_id:896fa122-a994-4ec1-6ac0-1af149ef9580 response_time:0.041984457 app_id:012b7380-c96c-46e6-a57e-b96fd1f7266c\n","origin":"router__1","source_instance":"1","source_type":"RTR","time":"2017-01-23T19:17:45Z","timestamp":1485199065878351999}

&amp;lt;6&amp;gt;2017-01-23T19:17:45Z 2ejr1t83au3 doppler[19]: {"cf_app_id":"3e0f31ee-f09c-46bf-a072-baef9e0c7763","cf_app_name":"nam-ccp-eureka-lab","cf_ignored_app":false,"cf_org_id":"dfeebb94-7a1c-4889-aa76-bb77852e434d","cf_org_name":"NAM-US-CCP","cf_origin":"firehose","cf_space_id":"b2abf80f-0543-4578-88d2-e7222f3d7b70","cf_space_name":"LAB","deployment":"cf","event_type":"LogMessage","ip":"168.72.205.254","job":"router-partition-a2833c853cfafee70104","job_index":"1","level":"info","message_type":"OUT","msg":"nam-ccp-eureka-lab.cfapps-gcg-gtdc1.citipaas-dev.dyn.nsroot.net - [23/01/2017:19:17:45 +0000] \"GET /eureka/apps/delta HTTP/1.1\" 200 0 89 \"-\" \"Java-EurekaClient/v1.4.6\" 153.40.245.130:46769 x_forwarded_for:\"168.72.205.134\" x_forwarded_proto:\"http\" vcap_request_id:4a46950c-7d18-4bed-7c98-833891c3358c response_time:0.001204662 app_id:3e0f31ee-f09c-46bf-a072-baef9e0c7763\n","origin":"router__1","source_instance":"1","source_type":"RTR","time":"2017-01-23T19:17:45Z","timestamp":1485199065824270851}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 23 Jan 2017 19:41:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258144#M77329</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2017-01-23T19:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258145#M77330</link>
      <description>&lt;P&gt;not sure this question is properly posted in forum or not.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 22:25:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258145#M77330</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2017-01-23T22:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258146#M77331</link>
      <description>&lt;P&gt;You are looking for the spath command, which pulls data out of JSON format.  Here's a sample.  The first two lines were how I put your first sample event into the system.  The third line pulls the JSON data out of the _raw event into a field named source, and the last line decodes the JSON data. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults
| eval _raw=
"\&amp;lt;6\&amp;gt;2017-01-23T19:17:45Z v204vtn756h doppler\[19\]: {\"cf_app_id\":\"012b7380-c96c-46e6-a57e-b96fd1f7266c\",\"cf_app_name\":\"nam-ccp-psg-sit\",\"cf_ignored_app\":false,\"cf_org_id\":\"fd12558e-ddaf-4dd2-91b3-85f28ccd27f3\",\"cf_org_name\":\"NAM-US-CCP\",\"cf_origin\":\"firehose\",\"cf_space_id\":\"f9e2c3b9-ff7a-46b2-b359-9ec4ec13487b\",\"cf_space_name\":\"lab\",\"deployment\":\"cf\",\"event_type\":\"LogMessage\",\"ip\":\"168.72.186.232\",\"job\":\"router-partition-ee9c6bad3843f162447f\",\"job_index\":\"1\",\"level\":\"info\",\"message_type\":\"OUT\",\"msg\":\"nam-ccp-psg-sit.cfapps-gcg-nonprd.nam.nsroot.net - \[23/01/2017:19:17:45 \+0000\] \\\"POST /public/sso/keepalive HTTP/1.1\\\" 200 0 0 \\\"-\\\" \\\"Apache-HttpClient/4.1.1 (java 1.5)\\\" 153.40.245.130:15583 x_forwarded_for:\\\"169.193.222.122\\\" x_forwarded_proto:\\\"http\\\" vcap_request_id:896fa122-a994-4ec1-6ac0-1af149ef9580 response_time:0.041984457 app_id:012b7380-c96c-46e6-a57e-b96fd1f7266c\\n\",\"origin\":\"router__1\",\"source_instance\":\"1\",\"source_type\":\"RTR\",\"time\":\"2017-01-23T19:17:45Z\",\"timestamp\":1485199065878351999}"

| rex field=_raw "(?&amp;lt;source&amp;gt;{[^}]*})"
| spath input=source
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Judging from the output, there may be some issue either with &lt;EM&gt;your JSON data&lt;/EM&gt; or with &lt;EM&gt;my manual escaping&lt;/EM&gt; of the special characters, after message_type and before msg.  &lt;/P&gt;

&lt;P&gt;Try those last two lines against your input, and see if they work.  If not, then I'll have to debug your JSON data.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 23:22:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258146#M77331</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-01-23T23:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258147#M77332</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
the output i pasted,that is from splunk log.&lt;BR /&gt;
from the output,i would like to extract &lt;/P&gt;

&lt;P&gt;ACTION=POST &lt;BR /&gt;
URI=/public/sso/keepalive&lt;BR /&gt;
response_time=0.041984457&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 23:40:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258147#M77332</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2017-01-23T23:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258148#M77333</link>
      <description>&lt;P&gt;so try those last two lines and see which values get extracted.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | rex field=_raw "(?&amp;lt;source&amp;gt;{[^}]*})"
 | spath input=source
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 24 Jan 2017 00:27:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258148#M77333</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-01-24T00:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258149#M77334</link>
      <description>&lt;P&gt;thanks DalJeanis,i tried but its not working.&lt;/P&gt;

&lt;P&gt;i was able to get it from field extractions , here it is &lt;BR /&gt;
rex field=_raw  "response_time:(?P[^ ]+)"&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:34:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258149#M77334</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2020-09-29T12:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258150#M77335</link>
      <description>&lt;P&gt;Try something like this. The data that you need is under msg field of embedded json data.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search | rex "msg\":\"([^\"]+)\"(?&amp;lt;Action&amp;gt;\w+)\s+(?&amp;lt;URI&amp;gt;\S+).+response_time:(?&amp;lt;response_time&amp;gt;\S+)" 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 24 Jan 2017 00:41:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258150#M77335</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-01-24T00:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258151#M77336</link>
      <description>&lt;P&gt;As long as you don't need any of the rest of the JSON data, that's a better way to go.  &lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;No, after re-reading your question, it isn't.  If you want all the fields to be available, then you need to unpack that JSON data.&lt;/P&gt;

&lt;P&gt;I'll post a new answer and we'll work from there.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 00:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258151#M77336</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-01-24T00:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258152#M77337</link>
      <description>&lt;P&gt;i just tried but it is not showing extracted fields in left side.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 00:47:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258152#M77337</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2017-01-24T00:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258153#M77338</link>
      <description>&lt;P&gt;Take your extract and put this after it &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| head 5 
| rex field=_raw "(?&amp;lt;source&amp;gt;{[^}]*})"
| spath input=source
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Look at the output fields and tell me what you see.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 00:52:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258153#M77338</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-01-24T00:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258154#M77339</link>
      <description>&lt;P&gt;ON my system it successfully extracted these values - &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cf_app_id   012b7380-c96c-46e6-a57e-b96fd1f7266c
cf_app_name nam-ccp-psg-sit
cf_ignored_app  FALSE
cf_org_id   fd12558e-ddaf-4dd2-91b3-85f28ccd27f3
cf_org_name NAM-US-CCP
cf_origin   firehose
cf_space_id f9e2c3b9-ff7a-46b2-b359-9ec4ec13487b
cf_space_name   lab
deployment  cf
event_type  LogMessage
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That's not all the fields you need, but I need to know whether your system operates as mine does, or if there's another issue as well.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 00:53:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258154#M77339</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-01-24T00:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258155#M77340</link>
      <description>&lt;P&gt;the fields above you mentioned,those are already extracted in splunk machine.&lt;BR /&gt;
particularly i was looking for these key and pair values&lt;/P&gt;

&lt;P&gt;ACTION=POST &lt;BR /&gt;
URI=/public/sso/keepalive&lt;BR /&gt;
response_time=0.041984457&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 01:14:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258155#M77340</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2017-01-24T01:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258156#M77341</link>
      <description>&lt;P&gt;Please post what you DO see, NOT what you don't.  &lt;/P&gt;

&lt;P&gt;I can't figure out where your code is breaking if I don't know what your code is doing right.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 15:13:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258156#M77341</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-01-25T15:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258157#M77342</link>
      <description>&lt;P&gt;How about this?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;your base search | rex "msg\":([^\"]+)\"(?&amp;lt;Action&amp;gt;\w+)\s+(?&amp;lt;URI&amp;gt;\S+)" | rex "response_time:(?&amp;lt;response_time&amp;gt;\S+)" 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 25 Jan 2017 15:25:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258157#M77342</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-01-25T15:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258158#M77343</link>
      <description>&lt;P&gt;i see these after running below search &lt;/P&gt;

&lt;P&gt;myindex| cf_org_name="&lt;EM&gt;" cf_space_name="&lt;/EM&gt;" cf_app_name="&lt;EM&gt;" | head 5| rex field=_raw "(?{[^}]&lt;/EM&gt;})"   | spath input=test| top limit=20 test&lt;/P&gt;

&lt;P&gt;{"cf_app_id":"ffbf3337-4e42-4cba-8fc7-b803c780e245","cf_app_name":"nam-ccp-fintech-idssink","cf_ignored_app":false,"cf_org_id":"67caccf2-a9f9-4a75-ae14-29f853f34c66","cf_org_name":"NAM-US-FINTECH","cf_origin":"firehose","cf_space_id":"ca745890-35a1-4e50-9043-688635d00f81","cf_space_name":"CCP-SIT4","deployment":"cf","event_type":"LogMessage","ip":"168.72.205.52","job":"diego_cell-partition-3d73afa5a8e5acc6f4c1","job_index":"5","level":"info","message_type":"OUT","msg":"Exit status 0","origin":"rep","source_instance":"0","source_type":"HEALTH","time":"2017-01-25T18:43:28Z","timestamp":1485369808983251121}&lt;/P&gt;

&lt;P&gt;{"cf_app_id":"b77b7b3b-5bad-44f9-8cfd-14b28cd6f6ba","cf_app_name":"CCP-EUREKA-DEV2","cf_ignored_app":false,"cf_org_id":"67caccf2-a9f9-4a75-ae14-29f853f34c66","cf_org_name":"NAM-US-FINTECH","cf_origin":"firehose","cf_space_id":"100f814a-2e29-43f8-8f05-3b52ce7a8a94","cf_space_name":"CARDS-MS-DEV2","deployment":"cf","event_type":"LogMessage","ip":"168.72.205.254","job":"router-partition-a2833c853cfafee70104","job_index":"1","level":"info","message_type":"OUT","msg":"ccp-eureka-dev2.cfapps-gcg-gtdc1.citipaas-dev.dyn.nsroot.net - [25/01/2017:18:43:28 +0000] \"POST /eureka/peerreplication/batch/ HTTP/1.1\" 200 224 37 \"-\" \"Java-EurekaClient-Replication/v1.4.6\" 153.40.245.130:46346 x_forwarded_for:\"168.72.205.77\" x_forwarded_proto:\"http\" vcap_request_id:60cfd3ed-b13c-4abe-6eb3-4d2902656ead response_time:0.001880901 app_id:b77b7b3b-5bad-44f9-8cfd-14b28cd6f6ba\n","origin":"router__1","source_instance":"1","source_type":"RTR","time":"2017-01-25T18:43:28Z","timestamp":1485369808995466909}&lt;/P&gt;

&lt;P&gt;{"cf_app_id":"46486cba-6d5a-4fe3-9d0d-01b7d5f24d53","cf_app_name":"crs-fcom-contserv-plat","cf_ignored_app":false,"cf_org_id":"0f0d0b56-fff2-48e8-9cf4-8d0c1259e910","cf_org_name":"NAM-US-CRS","cf_origin":"firehose","cf_space_id":"37a1eda4-58ca-4a43-852a-ad77752a3227","cf_space_name":"SIT3","deployment":"cf","event_type":"LogMessage","ip":"168.72.186.89","job":"diego_cell-partition-ee9c6bad3843f162447f","job_index":"22","level":"info","message_type":"OUT","msg":"DEBUG [l-4626-thread-7] c.c.ccp.localcache.impl.CacheMap c.c.c.l.i.CacheMap.put(CacheMap.java:52) - |||||||||111#C#459","origin":"rep","source_instance":"0","source_type":"APP","time":"2017-01-25T18:43:28Z","timestamp":1485369808996339080}&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:35:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258158#M77343</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2020-09-29T12:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258159#M77344</link>
      <description>&lt;P&gt;i got these fields&lt;/P&gt;

&lt;P&gt;cf_app_id&lt;BR /&gt;
cf_app_name&lt;BR /&gt;
cf_org_name&lt;BR /&gt;
cf_ignored_app&lt;BR /&gt;
cf_org_id&lt;BR /&gt;
cf_origin&lt;BR /&gt;
cf_session_id&lt;BR /&gt;
cf_space_id&lt;BR /&gt;
cf_space_name&lt;BR /&gt;
deployment&lt;BR /&gt;
event_type&lt;BR /&gt;
ip&lt;BR /&gt;
job&lt;BR /&gt;
job_index&lt;BR /&gt;
level&lt;BR /&gt;
message_type&lt;BR /&gt;
msg&lt;BR /&gt;
origin&lt;BR /&gt;
source_instance&lt;BR /&gt;
source_type&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:35:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258159#M77344</guid>
      <dc:creator>rajgowd1</dc:creator>
      <dc:date>2020-09-29T12:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract values from my sample log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258160#M77345</link>
      <description>&lt;P&gt;Hai, I am also looking for the same solution similar to what you discussed. Did you got to know how to achieve this.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 15:02:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extract-values-from-my-sample-log/m-p/258160#M77345</guid>
      <dc:creator>harishhari390</dc:creator>
      <dc:date>2020-02-25T15:02:01Z</dc:date>
    </item>
  </channel>
</rss>

