Getting Data In

How to split events into multiple events based on field a paricular string tag in raw log

raj_mpl
Path Finder

Hi All,
In search head for a single event I can see below kind of data (single event)

tag field1="123" field2="abc" field3="yes"
/tag
Sometext
tag field1="766" field2="hjh" field3="no"
/tag
Sometext
tag field1="103" field2="anc" field3="yes"
/tag
Sometext

In search head I can able to see field1 as a field but the values in that are storing randomly (above kind f events are there)
How to split the single event into multiple events based on string or field in above ?

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...