Getting Data In

Using SPATH notation in conf files

danielwysockiar
Explorer

Hi guys,
I need to uto extract fields and values during search time using SPATH notation in props.conf and transforms.conf filles.
I know that there are more convinient ways to do that, but I have to do it this way.

I know how to use spath in SPL, but can someone let me know what the syntax in the .conf file should look like?
I cannot not find it in any docs or answers.
Thank in advance.

0 Karma

sudosplunk
Motivator

Hi,

Are you looking for this?

alt text

0 Karma

danielwysockiar
Explorer

Not exactly, I need search-time extraction defined in .conf files, not indexed extractions.
I can not find how to use spath in props.conf.

0 Karma

sudosplunk
Motivator

KV_MODE is used for search-time field extractions only. These are the values you can set for KV_MODE,

  • none: if you want no field/value extraction to take place.
    • auto: extracts field/value pairs separated by equal signs.
    • auto_escaped: extracts fields/value pairs separated by equal signs and honors \" and \ as escaped sequences within quoted values, e.g field="value with \"nested\" quotes"
    • multi: invokes the multikv search command to expand a tabular event into multiple events.
    • xml : automatically extracts fields from XML data.
    • json: automatically extracts fields from JSON data.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...