Can someone help me to parse the fields either at indexing or through searches? Splunk detects the default fields as enterprises.48099.1.1.1/enterprises.48099.1.1.2 etc., . but we only need the value inside the quotations like below.
enterprises.48099.1.1.2 = STRING: "Monitoring error (SQL Server data collection)". But we need field as below:
field1 = Monitoring error (SQL Server data collection)
Here's one way. Since all of the strings you want to extract have no unique identifier, this rex command will pull them all into a multivalue field called 'fields'. Then you can use mvindex to access the individual fields.