Hi,
I am having events,
Number1=ABCDAS Number2=10
Number1=hsd gdsf Number2=1
Number1=ADG FHK Number2=11
Number1=HGSF Number2=4
I would like to extract the field value of Number1, Field value does not displaying any value after space in Splunk fields.
Probably regex will help to extract ABCDAS, hsd gdsf, ADG FHK, HGSF
Could anybody help to extract?
Number1 & Number2 are constant fields...
Your question is not at all clear, presumably because English is not your first language, but as I understand it you are specifically referring to cases 2 and 3 in your example, where you have embedded spaces in the field value. Have you tried redefining the field using the interactive field extractor?
To extract interactively using a manual search you need something like the following to extract to a field name that you can then use:
{search} | rex "Number1=(?<yourfield>.*) +Number2="
Your question is not at all clear, presumably because English is not your first language, but as I understand it you are specifically referring to cases 2 and 3 in your example, where you have embedded spaces in the field value. Have you tried redefining the field using the interactive field extractor?
To extract interactively using a manual search you need something like the following to extract to a field name that you can then use:
{search} | rex "Number1=(?<yourfield>.*) +Number2="
This is awesome, working exactly what I expected, Thank you very much grijhwani...