Splunk Search

Extract fields/subfields into table pipe and ":" delimited and name columns in fly

arunsubram
Explorer

My search string "[.Id.IdCreateService] - Promotion Created, Promotion Settings For PromoCode=121509PromoId=3550966 : 17429150|Gillette|111082|9999999|Save $5.00 on Gillette|Save $5.00 on ONE Gillette Fusion ProShield Razor|2016-04-29T07:00:00Z|2016-05-02T07:00:00Z|2016-07-02T07:00:00Z||811000474001215093500110100|JM|[047400656048, 047400656055]|[]||RetailerBanners : [Banner1]"

Fields are pipe delimited but the 3rd column as highlighted in Bold Italic starts after ":" and would need to name them as column 1,2..as below. Appreciate any suggestions.

Want to extract fields into a table like

PromoCode PromoId Column 1 Column 2 Column 3 Column 4 Column 5 Column 6 Column 7 Column 8 Column 9 Column 10
121509 3550966 17429150 Gillette 111082 9999999 Save $5.00 on Gillette Save $5.00 on ONE Gillette Fusion ProShield 2016-04-29T07:00:00Z 2016-05-02T07:00:00Z 2016-07-02T07:00:00Z

Tags (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

Please see the answer for your other question here. I think this ended up being a duplicate, or near enough. If that is indeed the case, let me know and I'll delete it as a dupe.

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...