Hi ,
I have events in following format
Subject Maths English Science
Marks1 95 98 96
Marks2 9 8 10
I want to extract subject name and marks2 value and display in an tabular format for all the events.
How can this be achieved.
Output table expected is
"Timestamp of event" Maths English Science
25-12-2012 9 8 10
Thank you
You should be able to use multikv
for this.
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Multikv
You should be able to use multikv
for this.
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Multikv
Thanks .This was what i wanted.