- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Extract Command to process single or double quotes
youngc_splunk

Splunk Employee
09-08-2021
11:06 PM
Hello Gurus!
I am sure some people may have run in to this. I am using extract command to parse fields from multi line unstructured event, but the data values are encapsulated by single quotes.
Here is the example :
====EVENT 1========
2021-09-08 00:00:00 ABC status - performance event
name : 'James Bond'
address : 'USA'
age : '100'
occupation : 'spy'
performance event END
==================
So the the following event, I am using transforms to
transforms.conf
[performance_data]
DELIMS = "\r\n", ":"
So above transforms partially works. The problem is the values has single quote ' encapsulated.
Like this
Field name "name" with value "'James Bond'". single quote included. How can I get rid of the single quote?
