Splunk Search

How to extract data from quotation marks?

Lazous
Engager

Hello, 
I am trying to extract the data from the following message:
the header data is in quotes and for each header data there is a set of secondary data also in quotes.
The events are presented as follows:

{Name=SS, PId=236}
PROD {Type=A_OUTGOING, Id=7934,plan=8975, Conflict=2529, Date=2023-04-18T18:51:00.000+02:00}
PROD {Type=B_OUTGOING, Id=7934, plan=8975, Conflict=72482, Date=2023-04-18T18:51:00.000+02:00}
{Name=DAG, PId=55}
PROD {Type=B_INCOMING, Id=7921, plan=8975, Conflict=64870, Date=2023-04-18T18:51:00.000+02:00}

The following result is expected:

Name   PId  Type  Id  plan Conflict  Date
SS 236 A_OUTGOING 7934 8975 2529 2023-04-18T18:51:00.000+02:00
SS 236 B_OUTGOING 7934 8975 72482 2023-04-18T18:51:00.000+02:00
DAG 55 B_INCOMING 7921 8975 64870 2023-04-18T18:51:00.000+02:00

 

Would you please help? Thanking you

Labels (1)
0 Karma

woodcock
Esteemed Legend

That data is JSON so the quick/easy/wrong fix is just to add this to your search:
| kv

But the better answer is to add this to your props.conf for your source/sourcetype:
KV_MODE = json

0 Karma

Lazous
Engager

i tried adding the | kv,

and i do not get all the data  in the result set.

am not allowed to edit the  props.conf

0 Karma

woodcock
Esteemed Legend

| makeresults
| eval raw="{Name=SS, PId=236}
PROD {Type=A_OUTGOING, Id=7934,plan=8975, Conflict=2529, Date=2023-04-18T18:51:00.000+02:00}
PROD {Type=B_OUTGOING, Id=7934, plan=8975, Conflict=72482, Date=2023-04-18T18:51:00.000+02:00} {Name=DAG, PId=55}
PROD {Type=B_INCOMING, Id=7921, plan=8975, Conflict=64870, Date=2023-04-18T18:51:00.000+02:00}"
| makemv delim="
" raw
| mvexpand raw
| rename raw AS _raw
| kv

ITWhisperer
SplunkTrust
SplunkTrust

Given that this looks like it might be JSON, have you tried using spath?

0 Karma

Lazous
Engager

would you please specify how the command would look like in this case ? 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...