Splunk Search

Value pairs are not automatically being parsed.

hjs123
New Member

Hey guys,

Splunk value pairs are not being automatically parsed. for example

USER=obama
AGE=18

should automatically fieldify "USER", "AGE". but not doing that. I check different conf for any changes in default/props.conf & default/transforms.conf, but can't find any issues.

Any ideas? gurus?

Tags (1)
0 Karma

vidda42
Explorer

Hey !

You can deal with Transforms/Extract.

1) Create a Transform with :

- Regex : (\w+)=([\w\d]+)
- Source Key : _raw
- Format : $1::$2

2) Associate that Transform with an Extract pointing to your source.

& you're done ! 🙂

David

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Can you post the full event? Splunk will automatically parse out fieds with the '=' sign only. You could easily make a config change to get comma delimited fields though.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...