I have a field on my events that has the following:
nothing to report
I am trying to create two fields from this. Field1 is called employee, and field2 would be employeeid. I want my end product to look like this:
The problem is that sometimes the events have 1 employe, other times more then one, and the field can also be empty.
I have been trying to achieve this with makemv or extract|kv with no successful results.
How would you guys/gals go about getting this done?
I would use a named transform with a regular expression, and use MV_ADD = true. You'll have to tie the transform to the sourcetype with a REPORT-... stanza in props.conf.
MV_ADD = true
In that case, I might look at "mvexpand". The props / transforms that I described above creates a multi-valued field. mvexpand takes each of those values and splits it into its own event.
Awesome! That seem to have worked for the field=value part. Now, what do I need to do so that each field=value has its own event?