Splunk Search

How can I use props and transforms to extract multiline muntivalue event?

nareshinsvu
Builder

Hi experts there,

Trying to extract multivalue output from a multiline json field through props and transforms. How best can I achieve for the below sample data (for my_mvdata field) ?

I can write a regex in pros.conf with \\t delimiter. But only getting the first line. How to use multi add and do it through transforms? 

 

 

 

 

 

{
something: false
somethingelse: true
blah:
blah:
my_mvdata: server1	count1	country1	code1	message1
server2	count1	country1	code1	message2
server3	count1	country1	code1	message3
server4	count1	country1	code1	message4
blah:
blah:
}

 

 

 

 

 

 

Labels (1)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @nareshinsvu,

this seems to be a json format, so use on your props.conf:

INDEXED_EXTRACTIONS = JSON

remember that only for this parameter, it's mandatory to put the props.conf both on Universal Forwarders, Indexers and Search Heads.

Ciao.

Giuseppe

0 Karma

nareshinsvu
Builder

Sure @gcusello , and what else should I put in the conf files to extract that fields as multivalued

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @nareshinsvu,

the above option is useful to extract all the fields as multivalue.

in addition you should add also 

SHOULD_LINEMERGE = true

but in my opinion, the best approach is:

  • take a sample of your logs in a file,
  • ingest it using the GUI guided procedure to choose the correct sourcetype,
  • copy the found sourcetype in all the systems interested to this ingestion.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...