Hi everyone, I need some help with extracting the field 'message' from my logs coming to splunk. Right now, I am able to see this field coming in as :
message=job py process completed successfully
When I extract this field, message, only 'job' is coming through. I am assuming this is because splunk can only read the first word, since they are all being seperated by spaces. Any way that I can fix this through Splunk or is this something I need to fix when formatting my logs through my application code?
@christinaef07 you can use below regex to extract whole string in message . below regex will extract everything after `message=` in message field.
...|rex "message(?<message>.*)"