Splunk Search

How can I use props and transforms to extract multiline muntivalue event?

nareshinsvu
Builder

Hi experts there,

Trying to extract multivalue output from a multiline json field through props and transforms. How best can I achieve for the below sample data (for my_mvdata field) ?

I can write a regex in pros.conf with \\t delimiter. But only getting the first line. How to use multi add and do it through transforms? 

 

 

 

 

 

{
something: false
somethingelse: true
blah:
blah:
my_mvdata: server1	count1	country1	code1	message1
server2	count1	country1	code1	message2
server3	count1	country1	code1	message3
server4	count1	country1	code1	message4
blah:
blah:
}

 

 

 

 

 

 

Labels (1)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @nareshinsvu,

this seems to be a json format, so use on your props.conf:

INDEXED_EXTRACTIONS = JSON

remember that only for this parameter, it's mandatory to put the props.conf both on Universal Forwarders, Indexers and Search Heads.

Ciao.

Giuseppe

0 Karma

nareshinsvu
Builder

Sure @gcusello , and what else should I put in the conf files to extract that fields as multivalued

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @nareshinsvu,

the above option is useful to extract all the fields as multivalue.

in addition you should add also 

SHOULD_LINEMERGE = true

but in my opinion, the best approach is:

  • take a sample of your logs in a file,
  • ingest it using the GUI guided procedure to choose the correct sourcetype,
  • copy the found sourcetype in all the systems interested to this ingestion.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...