I have this file with this appearance
first.prop.one=1
first.prop.two=2
first.prop.third=3
I was using KV_MODE=Auto
, but I need more than 100 results. So I went to the HF, in the sourcetype definitions added
[sourcetype]
EXTRACT-Property=(?<Property>.+)=(?<Value>.+)
But nothing changed. Am I extracting correctly ?
thanks
EXTRACT
and REPORT
are search time objects, and need to be in place on the search head (not the forwarder).
I'd also suggest setting KV_MODE = none
to avoid potential conflicts.
Ohhh right. Anyway, is the regex correct ?
It looks okay, but just to be sure I'd write it as (?<Property>[^=]+)=(?<Value>.+)