<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to deal with repeating fields in a single event in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-deal-with-repeating-fields-in-a-single-event/m-p/300513#M90475</link>
    <description>&lt;P&gt;More than likely this won't work, but you might able to try adding the following stanza to transforms.conf to extract them and turn them into fields automatically (don't forget to reference it from props.conf):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[get-params]
REGEX = Param=\"-(.+?)\s'(.+?)'\"
FORMAT = $1::$2
MV_ADD = true
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 22 Nov 2017 06:23:34 GMT</pubDate>
    <dc:creator>mtulett_splunk</dc:creator>
    <dc:date>2017-11-22T06:23:34Z</dc:date>
    <item>
      <title>How to deal with repeating fields in a single event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-deal-with-repeating-fields-in-a-single-event/m-p/300511#M90473</link>
      <description>&lt;P&gt;We noticed that Microsoft OWA logs produce a repeating field. How can we make them into individual ones instead of just picking up the first hit?&lt;/P&gt;

&lt;P&gt;E.g. the Param field in the log below. &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;11/17/2017 1:45:05 PM Server="SERVER" User="EMAIL@Email.com" Identity="stuff" Cmdlet="New-InboxRule" Param="-SubjectContainsWords 'Account limit has been exceeded'" Param="-DeleteMessage 'True'" Param="-Name 'Subject contains 'Account limit has been exceeded''" Param="-StopProcessingRules 'True'" Param="-Force 'True'" Param="-AlwaysDeleteOutlookRulesBlob 'True'" Success="True" Error="None"&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 04:41:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-deal-with-repeating-fields-in-a-single-event/m-p/300511#M90473</guid>
      <dc:creator>uhaba</dc:creator>
      <dc:date>2017-11-22T04:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to deal with repeating fields in a single event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-deal-with-repeating-fields-in-a-single-event/m-p/300512#M90474</link>
      <description>&lt;P&gt;you can extract fields by using props.conf and transforms.conf or extract from web-gui, you can also give different names like param1, param2 etc &lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 05:24:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-deal-with-repeating-fields-in-a-single-event/m-p/300512#M90474</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2017-11-22T05:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to deal with repeating fields in a single event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-deal-with-repeating-fields-in-a-single-event/m-p/300513#M90475</link>
      <description>&lt;P&gt;More than likely this won't work, but you might able to try adding the following stanza to transforms.conf to extract them and turn them into fields automatically (don't forget to reference it from props.conf):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[get-params]
REGEX = Param=\"-(.+?)\s'(.+?)'\"
FORMAT = $1::$2
MV_ADD = true
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 22 Nov 2017 06:23:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-deal-with-repeating-fields-in-a-single-event/m-p/300513#M90475</guid>
      <dc:creator>mtulett_splunk</dc:creator>
      <dc:date>2017-11-22T06:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to deal with repeating fields in a single event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-deal-with-repeating-fields-in-a-single-event/m-p/300514#M90476</link>
      <description>&lt;P&gt;It is a very informational and commendable update indeed.Even I was also looking out for the following.I want to include with it that I have been facing a problem regarding the GPS signal which is not found.I have tried out the troubleshooting procedures:&lt;BR /&gt;
1. Disabled the  Mock Locations. Step 1: On my Samsung Android smartphone, gone to Settings &amp;gt; About Phone.&lt;BR /&gt;
2. Toggled Airplane mode on/off.&lt;BR /&gt;
3. Reset Location Settings.&lt;BR /&gt;
4. Restarted the Phone.&lt;BR /&gt;
5. Retested the Network Settings.&lt;BR /&gt;
6. Updated the Pokémon GO.&lt;BR /&gt;
Suggest us anything else we need to include regarding the &lt;A href="https://mapsupdates.org/garmin-map-updates-free-download/"&gt;garmin map updates free download 2019&lt;/A&gt;  for the perfect resolution.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 06:26:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-deal-with-repeating-fields-in-a-single-event/m-p/300514#M90476</guid>
      <dc:creator>susan78</dc:creator>
      <dc:date>2020-04-08T06:26:19Z</dc:date>
    </item>
  </channel>
</rss>

