Hi sir/madam,
We have some files that fields are separated by |#|
. How can we define the field delimiter? We have tried |#|
directly, but failed.
For example:
57855114-e1d4-4787-961e-31e50784406d|#|2015-11-10 23:11:56|#|0|#|115.6.19.0|#|15891234567
If you have access to the conf files, you could define your delimiter there. Documentation here: http://docs.splunk.com/Documentation/Splunk/5.0.1/Knowledge/Createandmaintainsearch-timefieldextract...
If not, you can use the Web UI. You would go to settings > fields > transformations, and use a regex to pull out what you want.