Splunk Search

How to extract these individual fields for iostat data?

jodros
Builder

I am having a difficult time extracting fields for data returned by iostat. Has anyone been able to extract these individual fields? Data below:

Device   rReq_PS   wReq_PS   rKB_PS   wKB_PS  avgWaitMillis  avgSvcMillis  bandwUtilPct
sda       0.00     208.00     0.00    1644.00     1.45           0.02          0.50
sda1      0.00     0.00       0.00     0.00       0.00           0.00          0.00
sda2      0.00     0.00       0.00     0.00       0.00           0.00          0.00
sda5      0.00     208.00     0.00    1644.00     1.45           0.02          0.50
sda6      0.00     0.00       0.00     0.00       0.00           0.00          0.00
0 Karma

twinspop
Influencer

Does multikv not work for you?

| stats count | eval _raw="<your data above>" | multikv | fields - _raw count

Seems to work as expected.

Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...