When I perform index=testindex, I can see the field name "actions" and "activefeatures" with one or more array of strings e.g : ["abc","123,"fr","ereyhs"]. I wrote the rex in search query to extract the values and I now I can see the individual values are assigned to these fields.
index=test_index | rex field=actions "\"(?<actions_list>[^\"]+)[,\"]" max_match=20 | rex field=active_features "\"(?<active_features_list>[^\"]+)[,\"]" max_match=30
Please let me know how to move these 2 rex into props.conf and transforms.conf to search time extractions.
This should do:
transforms.conf [actions_list] SOURCE_KEY = actions REGEX = "(?<actions_list>[^"]+)[,"] REPEAT_MATCH = true MV_ADD = true [active_features_list] SOURCE_KEY = active_features REGEX = "(?<active_features_list>[^"]+)[,"] REPEAT_MATCH = true MV_ADD = true props.conf [your_sourcetype] REPORT-fields = actions_list,active_features_list
Note, this isn't 100% the same because these extractions won't stop at 20 or 30 values.
actionslist and activefeatureslist is not seen when I type index=testindex
actions and active_features fields are seen which where autoextracted with other REPORT commands.
Here is what in my props.conf
REPORT-json = report-json, report-json-kv
REPORT-fields = actionslist,activefeatures_list
REPORT-json extracts the JSON portion of event and key-values including actions & activelistfeatures fields.
To ensure the transforms are applied in the desired order you should move them into one list like this:
REPORT-fields = report-json,report-json-kv,actions_list,active_features_list
See http://docs.splunk.com/Documentation/Splunk/6.1.1/Admin/propsconf for reference.