Splunk Search

Examples using kvform?

Super Champion

Does anyone know of any examples of using the kvform search command. The kvform docs seem a bit sparse to me, and I haven't been able to locate any working examples. I'd like to see examples including input files and all configs involved and their locations relative to an app folder.

The docs are unclear on a few points:

  • What location should the form files be placed? (The docs talk about $PLUNK_HOME/etc/apps/.../form, but does that mean there's a folder called "form"? is it located under local or default.). I assume '...' is the app name.
  • Can you only extract one field at a time using the kvform search command?
  • Is it possible to setup automatic extraction for a specified sourcetype via props?

Splunk Employee
Splunk Employee

I am pretty sure it is broken.

Screen shot here:

Sample app here:

To replicate, import the sample data, ensure you are in the kvform_example app, and run this search:
source="students.txt" | kvform form=students

0 Karma


I will fourth that.

0 Karma


I will third that. Some documented examples would be nice.

0 Karma


I'd be interested to see this expanded out too. The documentation & examples are definitely lacking.

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>