I have this file with this appearance
I was using KV_MODE=Auto, but I need more than 100 results. So I went to the HF, in the sourcetype definitions added
But nothing changed. Am I extracting correctly ?
EXTRACT and REPORT are search time objects, and need to be in place on the search head (not the forwarder).
I'd also suggest setting KV_MODE = none to avoid potential conflicts.
KV_MODE = none
Ohhh right. Anyway, is the regex correct ?
It looks okay, but just to be sure I'd write it as (?<Property>[^=]+)=(?<Value>.+)