Splunk Search

Extract fields/subfields into table pipe and ":" delimited and name columns in fly

arunsubram
Explorer

My search string "[.Id.IdCreateService] - Promotion Created, Promotion Settings For PromoCode=121509PromoId=3550966 : 17429150|Gillette|111082|9999999|Save $5.00 on Gillette|Save $5.00 on ONE Gillette Fusion ProShield Razor|2016-04-29T07:00:00Z|2016-05-02T07:00:00Z|2016-07-02T07:00:00Z||811000474001215093500110100|JM|[047400656048, 047400656055]|[]||RetailerBanners : [Banner1]"

Fields are pipe delimited but the 3rd column as highlighted in Bold Italic starts after ":" and would need to name them as column 1,2..as below. Appreciate any suggestions.

Want to extract fields into a table like

PromoCode PromoId Column 1 Column 2 Column 3 Column 4 Column 5 Column 6 Column 7 Column 8 Column 9 Column 10
121509 3550966 17429150 Gillette 111082 9999999 Save $5.00 on Gillette Save $5.00 on ONE Gillette Fusion ProShield 2016-04-29T07:00:00Z 2016-05-02T07:00:00Z 2016-07-02T07:00:00Z

Tags (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

Please see the answer for your other question here. I think this ended up being a duplicate, or near enough. If that is indeed the case, let me know and I'll delete it as a dupe.

0 Karma
Get Updates on the Splunk Community!

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...