Getting Data In

Convert a string to table in splunk

bharat149
Explorer

Hi All i have result in the below format :
"From abc customerId YETNAKCNK, operation create,consumedUnits 0"
"From abc customerId YETNAKCNJ, operation update,consumedUnits 2"

I have to convert the below data to the following format : 
customerId               operation           consumedUnits

YETNAKCNK.             create                           0

YETNAKCNJ               update                          2

Tags (1)
0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

@bharat149 

Can you please try this?

YOUR_SEARCH
| rex field=_raw "customerId (?<customerId>.*),\soperation\s(?<operation>.*),consumedUnits\s(?<consumedUnits>.*)"
|table customerId operation consumedUnits

 

Sample Search

| makeresults 
| eval event="From abc customerId YETNAKCNK, operation create,consumedUnits 0|From abc customerId YETNAKCNJ, operation update,consumedUnits 2" 
| eval event=split(event,"|") 
| mvexpand event 
| rename event as _raw
| rex field=_raw "customerId (?<customerId>.*),\soperation\s(?<operation>.*),consumedUnits\s(?<consumedUnits>.*)"
|table customerId operation consumedUnits

View solution in original post

0 Karma

bharat149
Explorer

and if i want to apply filter for the customer Id

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

jus add
| where customerId="YETNAKCNK"

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@bharat149 

Can you please try this?

YOUR_SEARCH
| rex field=_raw "customerId (?<customerId>.*),\soperation\s(?<operation>.*),consumedUnits\s(?<consumedUnits>.*)"
|table customerId operation consumedUnits

 

Sample Search

| makeresults 
| eval event="From abc customerId YETNAKCNK, operation create,consumedUnits 0|From abc customerId YETNAKCNJ, operation update,consumedUnits 2" 
| eval event=split(event,"|") 
| mvexpand event 
| rename event as _raw
| rex field=_raw "customerId (?<customerId>.*),\soperation\s(?<operation>.*),consumedUnits\s(?<consumedUnits>.*)"
|table customerId operation consumedUnits
0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...