I have quoted parameters in log files, which are processed by Splunk:
"Version":"21"
How to extract that parameter to use in requests like this:
Version = "21" OR ...
Please note that it's no chance to modify current Splunk's config files.
(original question: stackoverflow #18897765)
You can try this:
your_search | extract kvdelim=":" | search Version="21"
This will pull the Key Value pairs that are delimited by a colon ":".
You can try this:
your_search | extract kvdelim=":" | search Version="21"
This will pull the Key Value pairs that are delimited by a colon ":".
|extract kvdelim=":" pairdelim=","
I tryed it with no luck. Example: "Model":"Lenovo K900_ROW","Android":"4.2.1","Date":"Mon Sep 30 23:58:27 GMT+03:00 2013","Build":"RC11","LastActivity":"ru.TextActivity","Version":"21""StackTrace":"java.lang.RuntimeException"...
wasn't found.