Splunk Search

How to get only second field=value from all events?

test_qweqwe
Builder

Hi.
I have 500 events where only second line of event have value for me.
How to get that information from all events?

Tags (1)

pradeepkumarg
Influencer

Can you provide some sample events and what you have tried so far?

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!