Getting Data In

Using SPATH notation in conf files

danielwysockiar
Explorer

Hi guys,
I need to uto extract fields and values during search time using SPATH notation in props.conf and transforms.conf filles.
I know that there are more convinient ways to do that, but I have to do it this way.

I know how to use spath in SPL, but can someone let me know what the syntax in the .conf file should look like?
I cannot not find it in any docs or answers.
Thank in advance.

0 Karma

sudosplunk
Motivator

Hi,

Are you looking for this?

alt text

0 Karma

danielwysockiar
Explorer

Not exactly, I need search-time extraction defined in .conf files, not indexed extractions.
I can not find how to use spath in props.conf.

0 Karma

sudosplunk
Motivator

KV_MODE is used for search-time field extractions only. These are the values you can set for KV_MODE,

  • none: if you want no field/value extraction to take place.
    • auto: extracts field/value pairs separated by equal signs.
    • auto_escaped: extracts fields/value pairs separated by equal signs and honors \" and \ as escaped sequences within quoted values, e.g field="value with \"nested\" quotes"
    • multi: invokes the multikv search command to expand a tabular event into multiple events.
    • xml : automatically extracts fields from XML data.
    • json: automatically extracts fields from JSON data.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...