Getting Data In

Using SPATH notation in conf files

danielwysockiar
Explorer

Hi guys,
I need to uto extract fields and values during search time using SPATH notation in props.conf and transforms.conf filles.
I know that there are more convinient ways to do that, but I have to do it this way.

I know how to use spath in SPL, but can someone let me know what the syntax in the .conf file should look like?
I cannot not find it in any docs or answers.
Thank in advance.

0 Karma

sudosplunk
Motivator

Hi,

Are you looking for this?

alt text

0 Karma

danielwysockiar
Explorer

Not exactly, I need search-time extraction defined in .conf files, not indexed extractions.
I can not find how to use spath in props.conf.

0 Karma

sudosplunk
Motivator

KV_MODE is used for search-time field extractions only. These are the values you can set for KV_MODE,

  • none: if you want no field/value extraction to take place.
    • auto: extracts field/value pairs separated by equal signs.
    • auto_escaped: extracts fields/value pairs separated by equal signs and honors \" and \ as escaped sequences within quoted values, e.g field="value with \"nested\" quotes"
    • multi: invokes the multikv search command to expand a tabular event into multiple events.
    • xml : automatically extracts fields from XML data.
    • json: automatically extracts fields from JSON data.
0 Karma
Get Updates on the Splunk Community!

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

Splunk New Course Releases for a Changing World

Every day, the world feels like it’s moving faster with new technological breakthroughs, AI innovation, and ...