Hi,
I'm trying to split this event into a
| name | value |
| FieldA | false |
| FieldB | 5 |
key-value table
org.Data@28c839cfname=FieldA, value=false, org.Data@49b45b79name=FealedB, value=5,
Query:
1. base_query | extract pairdelim=" ", kvdelim=" " | table _raw
2. base_query | extract pairdelim="org.data*=", kvdelim=" " | table _raw
is it possible?
Thanks
| rex max_match=0 "org.Data[^=]+=(?<name>[^,]+),\svalue=(?<value>[^,]+)"
| eval fieldvalue=mvzip(name, value)
| fields fieldvalue
| mvexpand fieldvalue
| rex field=fieldvalue "(?<name>[^,]+),(?<value>.+)"
| table name, value
| rex max_match=0 "org.Data[^=]+=(?<name>[^,]+),\svalue=(?<value>[^,]+)"
| eval fieldvalue=mvzip(name, value)
| fields fieldvalue
| mvexpand fieldvalue
| rex field=fieldvalue "(?<name>[^,]+),(?<value>.+)"
| table name, value