Splunk Search

How to make a field extraction for my sample data?

soniajin
New Member

UseCase to extract name that has "at: A_T "and group name by id?

TestData
"add[1]: HomeKit
abc: "22c4902d-"
id: X://A/AC=74AC3219-15AE--8CC6-BAFAFC6
homeId: X-HM://A/HM=A94A1A939A70-81D6DCE7B6C6
name: "Test1"
rs: "Test1"
at: A_T

add[2]: HomeKit
abc: "ae588e20-befc-4875-95b2-0945547f09dc"
id: X-HM://A/AC=BD8EC554-6828-5E2F-947F-DB98AD7669F9
homeId: ACCESSORY
name: "Test1"
rs: "Test1"
at: A_T

add[3]: HomeKit
abc: "ae588e20-befc-4875-95b2-0945547f09dc"
id: X-HM://A/AC=BD8EC554-6828-5E2F-947F-DB98AD7669F9
homeId: ACCESSORY
name: "Test2"
rs: "Test1"
at: A_T

add[4]: HomeKit
abc: "ae588e20-befc-4875-95b2-0945547f09dc"
id: X-HM://A/AC=BD8EC554-6828-5E2F-947F-DB98AD7669F9
homeId: ACCESSORY
name: "Test1"
rs: "Test1"
at: STR"

Tags (1)
0 Karma

efavreau
Motivator

What have you tried? Where are you getting stuck? Are you looking to do this at index time or search time?

###

If this reply helps you, an upvote would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...