Splunk Search

How to split a single line which contains multiple field values separated by spaces into multiple fields in Splunk?

pavanae
Builder

I have a csv file query as follows :- 

| inputlookup file_1.csv

which gives the result as follows in a single line as a single field or column 

A B C D E F G H

i j k l m n o p

q r s t u v w x

Now, I want to turn the above result as follows with multiple fields naming A, B,C,D,E,F,G,H basically what I am trying to acheive is convert the single field into multiple fields with each field name or field value is extracted based on a space separation in the single field from above?

ABCDEFGH
ijklmnop
qrstuvwx

 

 

Labels (4)

richgalloway
SplunkTrust
SplunkTrust

rex can do that for you.

| rex "(?<A>\S+)\s(?<A>\S+)\s(?<B>\S+)\s(?<C>\S+)\s(?<E>\S+)\s(?<F>\S+)\s(?<G>\S+)\s(?<H>\S+)\s"

It would be better if you could have the CSV file created as a true comma-separated value file.  Then Splunk would separate the fields automatically.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Splunk Cloud Application Management in Terraform

Now On-Demand   We’re diving into how you can bring Infrastructure as Code (IaC) principles to your Splunk ...

What's New in Splunk Enterprise Security (ES) 8.6

Purpose-Built AI Agents for the Agentic SOC  Splunk Enterprise Security 8.6 expands AI in Security with ...