- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Regex tokenizer when the multivalue field has values within an event that are not always connected in a structured way?
boris
Path Finder
04-13-2012
02:41 PM
I want to make my DATASET
field a multivalue field.
The regex extracting the field using Splunkweb's Field Extraction Manager page is:
(umi\.|%3D|,|%3B|\=|/catalog/w+/)(?P{DATASET}[a-z0-9_\-%]+)\.(geometry|\w*geom|\w+\.\w+)
The dataset values in an event are not delimited in an structured way.
An example event with 4 DATASET values:
"select=VALUE1,umi.VALUE2&from=VALUE3%BVALUE4.gemetry"
QUESTIONS:
- How should define my regex tokenizer for the DATASET field?
- Should I define tokenizer in
fields.conf
or in Splunkweb's Transform Manager page?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yannK

Splunk Employee
03-11-2014
02:55 PM
There is no manager for that.
you can test is with that in a search
<my search> | makemv tokenizer="([^,].*)" DATASET
then deploy a fields.conf to make it automatic
see http://docs.splunk.com/Documentation/Splunk/6.0.2/Knowledge/ConfigureSplunktoparsemulti-valuefields
