Splunk Search

Examples using kvform?

Lowell
Super Champion

Does anyone know of any examples of using the kvform search command. The kvform docs seem a bit sparse to me, and I haven't been able to locate any working examples. I'd like to see examples including input files and all configs involved and their locations relative to an app folder.

The docs are unclear on a few points:

  • What location should the form files be placed? (The docs talk about $PLUNK_HOME/etc/apps/.../form, but does that mean there's a folder called "form"? is it located under local or default.). I assume '...' is the app name.
  • Can you only extract one field at a time using the kvform search command?
  • Is it possible to setup automatic extraction for a specified sourcetype via props?

bshuler_splunk
Splunk Employee
Splunk Employee

I am pretty sure it is broken.

Screen shot here:
https://www.dropbox.com/s/3f4rj7468qoilln/Screenshot%202015-04-16%2007.29.02.png?dl=0

Sample app here:
http://d.pr/f/wF95

To replicate, import the sample data, ensure you are in the kvform_example app, and run this search:
source="students.txt" | kvform form=students

0 Karma

snoobzilla
Builder

I will fourth that.

0 Karma

Ricapar
Communicator

I will third that. Some documented examples would be nice.

0 Karma

rturk
Builder

I'd be interested to see this expanded out too. The documentation & examples are definitely lacking.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...