Have a search result as
GET https://…. | Status: 403 | Message: Forbidden | Duration: 166 | x-req-id: ssv5s-ssy67-78vshb | x-correlation-id: vsvsuj-75sys7-sbbjs7
Need to extract value of x-req-id .
Tried this extract pairdelim="|" , kvdelim=":" ,which gives Status & Message & Duration but not able to fetch x-req-id
This works for me - which version of splunk are you using?
| makeresults
| eval _raw="GET https://…. | Status: 403 | Message: Forbidden | Duration: 166 | x-req-id: ssv5s-ssy67-78vshb | x-correlation-id: vsvsuj-75sys7-sbbjs7"
| extract pairdelim="|" kvdelim=":"
Splunk 8.2.2.1
Same here - so does my run anywhere example work for you?
No its not working
Do you get any errors reported which might help determine what the issue might be other than "its not working"?