Hi,
I am new in splunk and i want to save the value in fields before and after =
for example  events look like below 
rollnumber=34556
class=12
I want to return rollnumber and class in first field and the number after = in second field.
base search | rex max_match=15 field=_raw "(?P)="
 this doesnt work, both values are coming as space. 
 
					
				
		
Your regex seems to be incomplete, could you try:
| rex max_match=15 field=_raw "(?P<field1>\w+)\=(?P<field2>\w+)" 
 
					
				
		
Your regex seems to be incomplete, could you try:
| rex max_match=15 field=_raw "(?P<field1>\w+)\=(?P<field2>\w+)" 
